Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15E146470E018627B00D362C0A575AFEAB3E1A380DB530685A3F8D39E9BD7D42DC17769 |
|
CONTENT
ssdeep
|
3072:yPHbLK7MLx+L7UJq96mmFUAnsjrIJrOjX:S6AuZy4jX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac2d93d2926cccc7 |
|
VISUAL
aHash
|
ff838181e7d3f3ff |
|
VISUAL
dHash
|
613b33330f332b3c |
|
VISUAL
wHash
|
ff818181c381e1ff |
|
VISUAL
colorHash
|
06600010000 |
|
VISUAL
cropResistant
|
613b33330f332b3c,cde9f1f5f575ac79,181d1193d38dace0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 71 techniques to evade detection by security scanners and make reverse engineering more difficult.