Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T137A319B031122A6B92F38AB1B2577B5572BD8B1EC80F85B4F1BCC1612BD8C5B6D13764 |
|
CONTENT
ssdeep
|
1536:WXridW35TpXridW35TW87QGvv7y3UfvQV:J8EGvmBV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c91c633ec13c673c |
|
VISUAL
aHash
|
023c18181800006c |
|
VISUAL
dHash
|
047130b2b20c90c8 |
|
VISUAL
wHash
|
82fcf8f8f8c0c06e |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
ff772b2b9e9fffff,047130b2b20c90c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.