Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154624030C42599330693B3F1A23E472F56E68398DE23161C2BF8471C6BD6E5ADF26958 |
|
CONTENT
ssdeep
|
96:C/N4muOEtE2TQQWWCn4M46MOcMdYc1DRMb6M8T3TdYcf2MP2MTTqTdYc+B/8I+Ns:eVGZW6wTb5LW5cUTw38KWfRnDa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99696693a966934d |
|
VISUAL
aHash
|
641838183c7c10ff |
|
VISUAL
dHash
|
dcf0f0f2d0d8a449 |
|
VISUAL
wHash
|
7e1838183c7e10ff |
|
VISUAL
colorHash
|
38002008018 |
|
VISUAL
cropResistant
|
f0c090b9b4b8c8f0,dcf0f0f2d0d8a449 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.