Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1411376B19065A537028AF2D0B636571F72C3878BD6870BA2A7FC431C1AC6ED2DE2751D |
|
CONTENT
ssdeep
|
768:Q2gMkvdq3FGMq6COFJQdC3gf6IgMkvdq3FGMq6COd2NhBFlVU8cTrJ/1MMiUeMD1:Q2gMkvdq3FGMq6COFJQdC3gfNgMkvdqJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e65613346ce6693 |
|
VISUAL
aHash
|
00383c3c3c1c3c3c |
|
VISUAL
dHash
|
495060616d797961 |
|
VISUAL
wHash
|
243c3c3c3c3c3e7c |
|
VISUAL
colorHash
|
08007000000 |
|
VISUAL
cropResistant
|
495060616d797961 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.