Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T162B3FE23415935270437C2D1356A6B3BD0B6D98FFAE70A415EDCC7F62AFACA0B05B119 |
|
CONTENT
ssdeep
|
1536:jUmtpR4nXBKpSpFl26vvqf+F2NnBUn0EoHmz7:jUM+qWOqJoGX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9717e81c19c74f70 |
|
VISUAL
aHash
|
00040004001cffff |
|
VISUAL
dHash
|
786ccc7cfc7c0023 |
|
VISUAL
wHash
|
00060e0e063fffff |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
6686a4cc43212140,8000619191210080,0000419191014180,949420988c64acac,6c000957564b2b73,786ccc4c6c5cbc7c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.