Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15943626065A0563F076B86F499BADF2B72D1A35AEA53048563FC53B83FDBC30F922411 |
|
CONTENT
ssdeep
|
1536:k4bz4KCDIQ34FwHvjdCODLl7WtB5QWIqWjbe+ueC8P:KlT7La5QW4J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
926de912926ded32 |
|
VISUAL
aHash
|
0000007e6e2e00ff |
|
VISUAL
dHash
|
d418c3ccccdc3348 |
|
VISUAL
wHash
|
7e00087e7e6e00ff |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
014040d0c0404000,d418e3cccccc3a04 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 511 techniques to evade detection by security scanners and make reverse engineering more difficult.