Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AC433332208EADBF25D353C473202E6AE1E0F355EB03464697F9835CCAD6E76AC63465 |
|
CONTENT
ssdeep
|
768:YTIOTI/dXbenDuZZr4YWcgGpRJ8ga+GftS+y1P3x5+12hnDw64zNMqnCHrK86N7h:UIiIpeDIZSrv4a6DDy/Drln+CqO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96b669693a9495d2 |
|
VISUAL
aHash
|
c064660644000000 |
|
VISUAL
dHash
|
86cccccc8cd0d4d4 |
|
VISUAL
wHash
|
f6f4f6f644287404 |
|
VISUAL
colorHash
|
300030000c0 |
|
VISUAL
cropResistant
|
a4a45386a4e254c0,86cccccc8cd0d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.