Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110631BD93884601A476790E3A0BB2A8AF7391C2F790C55E174B0CBE572B84F5616BF4F |
|
CONTENT
ssdeep
|
768:XHyWuP/SbyD5uWbcsCF9/5+GQ/u8n+11GQvzWvNwqSZXHLzLrfBz27p4qF5jwqcI:GuVQcyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f5650423339af0f |
|
VISUAL
aHash
|
00fc1f0f3f7f1f1f |
|
VISUAL
dHash
|
ccc87a5878603434 |
|
VISUAL
wHash
|
007c1f070fff0f0e |
|
VISUAL
colorHash
|
07030000200 |
|
VISUAL
cropResistant
|
ccc87a5878603434,45453398a4665545 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 477 techniques to evade detection by security scanners and make reverse engineering more difficult.