Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C532F30A410AA3B01EB85D99672675A72F98349D6230689FAF9C3ED0FDFC19DE37114 |
|
CONTENT
ssdeep
|
768:Y6a4444esiR/jZAs6j1p7qQO8LuwIVlCpJsyuhmXol2Itd268FamRhWCIB5Uf79F:za4444esiRKXzLb3xw2mdjawCIB+79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b503d3ba13d2d34a |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
dcc7fbde773b2aaa |
|
VISUAL
wHash
|
0403000703ffffff |
|
VISUAL
colorHash
|
1b1c8000000 |
|
VISUAL
cropResistant
|
3b00262b2b000202,d92cd7f1fcdef733 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 86 techniques to evade detection by security scanners and make reverse engineering more difficult.