Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15B434A73636278BD83CB82DDB7392F41B2C2A58DE9870490B59866DD27C3C8275877B4 |
|
CONTENT
ssdeep
|
1536:ax+EsZ/8leP0OMDTEe+wiMJBawPMJBKwZUXx+y9dQyDF1ZAU84HaXwI:a+DVwcwfUUXxpDzHy7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ef9190a4c03fac6b |
|
VISUAL
aHash
|
fff98191b18181ff |
|
VISUAL
dHash
|
cc71736347777169 |
|
VISUAL
wHash
|
fff98181818181ff |
|
VISUAL
colorHash
|
07038000000 |
|
VISUAL
cropResistant
|
cc71736347777169,c0c2d2bbabd2c2c0,0e363c6c5878340c,ffffec6d6afd6fe3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.