Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T145B33C743559B57766B343E3609B6203B278521B940E4830B364FDAE72ADCCEA077F85 |
|
CONTENT
ssdeep
|
1536:scCrXPvbpWpFo2h20VTgHd8tVPTMnEXCd0uq+wSRKF:EXspMug98nKd0+w1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b86799c3d298d949 |
|
VISUAL
aHash
|
fb81818783df8f8f |
|
VISUAL
dHash
|
0b0b333d2f3b3e34 |
|
VISUAL
wHash
|
fb818187019f8f8f |
|
VISUAL
colorHash
|
02400038000 |
|
VISUAL
cropResistant
|
0b0b333d2f3b3e34,ea6a5a5aeaaa1aa5,6ce4e4dce2612b23,1c2c676623233c64,010b3d272e4e0d9d,9f0d8d8720e16367,b63636ce2e69af16 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 66 techniques to evade detection by security scanners and make reverse engineering more difficult.