Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17873D621A41CE82E01E745D4B136472E72B98301D6534299F5FBE3EC9A9FC6EE937318 |
|
CONTENT
ssdeep
|
1536:fc77umsIxRRlSaSScStvpnRFSVtPqTMxsab:fc77umF3S5b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a7da89e4bad10a4d |
|
VISUAL
aHash
|
ffff000000000000 |
|
VISUAL
dHash
|
20f4d84c4ccec6c4 |
|
VISUAL
wHash
|
ffff280487636222 |
|
VISUAL
colorHash
|
19201008040 |
|
VISUAL
cropResistant
|
0032332324841c00,f0c84c4c4ec6c6d5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 87 techniques to evade detection by security scanners and make reverse engineering more difficult.