Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T116D287B0226169BF51C7C6F0F2656B5EA1B4C7D8C527C69CB3ECC2962FC6C69CD89210 |
|
CONTENT
ssdeep
|
384:H68X94zKtNTTr5Sjpfo1NXKf1t9r8LkKj9mpPqm/L9:x9qKtNkfo1NXKx8LkKs15j9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ad4083923b3eece3 |
|
VISUAL
aHash
|
7c72f1838f9f3f33 |
|
VISUAL
dHash
|
e9c6c63319236347 |
|
VISUAL
wHash
|
7c72f18195953533 |
|
VISUAL
colorHash
|
070060000c0 |
|
VISUAL
cropResistant
|
e9c6c63319236347 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 40 techniques to evade detection by security scanners and make reverse engineering more difficult.