Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F3430AE93895A016077390D3A0BF3A4AB339182FB91C55A0B174DFE571F84A5606BF8B |
|
CONTENT
ssdeep
|
768:ayWuP5yLuLW//uMRWXbz8vL8n+UsfM15/FijwqqBSDC9CAX8Ue++c9T7uhQ4Suxf:FTyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d2d656d65213d3c |
|
VISUAL
aHash
|
033f1f3f1f1fffff |
|
VISUAL
dHash
|
967276c6766e4a4e |
|
VISUAL
wHash
|
033f0f3f031b2727 |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
967276c6766e4a4e,0000047871792916 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 700 techniques to evade detection by security scanners and make reverse engineering more difficult.