Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T107B3A832612D753F274786D4B726676A719FC34ACD8246D282FD83B90BB7CA0EE17448 |
|
CONTENT
ssdeep
|
3072:M5YwprqG7nrqGIpKH6ipKH6ozpKH6Tq+kpYwS:Pq+ks |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b838c6c6d1787a95 |
|
VISUAL
aHash
|
fd0f8189cf87ffff |
|
VISUAL
dHash
|
613b3b1b1b3f6c62 |
|
VISUAL
wHash
|
dd0100818b83ffff |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
613b3b1b1b3f6c62,7cf8b9ccf85d9705,754423d4d4d43b50 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 83 techniques to evade detection by security scanners and make reverse engineering more difficult.