Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T136736070A461D93B01CFA6C4A632172A62EA8345CA4343D9F6F8C7AA4FDFC69CD33554 |
|
CONTENT
ssdeep
|
1536:tXa+IreeeveeekeeeWeeefeeefeeeL+Cci7C1/lVsIxldg73u:U7C1Tp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9e30c3e5c638d23 |
|
VISUAL
aHash
|
01efefec6c180018 |
|
VISUAL
dHash
|
3318dadc58717170 |
|
VISUAL
wHash
|
01ffefecec181818 |
|
VISUAL
colorHash
|
32c02000000 |
|
VISUAL
cropResistant
|
a280a2a2a2a2a0a2,3318dadc58717170 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 32 techniques to evade detection by security scanners and make reverse engineering more difficult.