Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA03943060506A3B41C3D3D6A334AB1FA3C2C286DA634B4867F5C7AD9FDBDA1DD25264 |
|
CONTENT
ssdeep
|
768:ijIK7wJRuua+JqU79JC+EWz/MGjLdVGlH+K0Pm:ijIK7wJRuua+JquC+EWz/MMpVdm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9417fa688c0979d7 |
|
VISUAL
aHash
|
0000261e0240ffff |
|
VISUAL
dHash
|
b1ccccf476979924 |
|
VISUAL
wHash
|
00000e3f22cbffff |
|
VISUAL
colorHash
|
0f007000000 |
|
VISUAL
cropResistant
|
383c3c3d246e6666,f656979799d020ae,b1ccccccf476979b,6b636366e6030127 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.