Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1251473307217483A956F52DBD149574CA0C6D3CBD2421EE8F3F0522ECFA2EA5BE76264 |
|
CONTENT
ssdeep
|
3072:aroa1ipoAli4lx+3IRRu1Q1D1Z1O1g314165r3Fh6EvoCK:aca1iCAli4b+3I+1Q1D1Z1O1K14165r+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
da4a87b6953d2546 |
|
VISUAL
aHash
|
bcf8d8d8fcfffffe |
|
VISUAL
dHash
|
70013133392910cc |
|
VISUAL
wHash
|
18f888888c8fffe6 |
|
VISUAL
colorHash
|
07e00008040 |
|
VISUAL
cropResistant
|
70013133392910cc,8c8d1633b6669792 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1168 techniques to evade detection by security scanners and make reverse engineering more difficult.