Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11AE3EA79B20C11AA4197A8C4E830FF9971C2EB8EC319C5122768A7459FF3DE178975EC |
|
CONTENT
ssdeep
|
768:l6ZeDwzOmo1NKkHKBX+4zfMv8QJOhnHBR6AtC:oe/mo18kHKBO4zfMv8QUhnHBR6A8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a7701fdcc08fe00f |
|
VISUAL
aHash
|
004042fffff83f3f |
|
VISUAL
dHash
|
de5e8eaca444646a |
|
VISUAL
wHash
|
000000fffff03f3f |
|
VISUAL
colorHash
|
07400038000 |
|
VISUAL
cropResistant
|
de5e8eaca444646a,29d4cc69b2ccf649,1b27393d796e6c5e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 94 techniques to evade detection by security scanners and make reverse engineering more difficult.