Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17D635231D041A82743D78AC85276672A63E78349CB530A48BAF883EE5FDFD68DD33519 |
|
CONTENT
ssdeep
|
768:AWsIx/jrlAt8U2SSSp0SeISkr0YoUf7rqqiYJ:AWsIxFSSSp0SeISJYX7GZYJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aadad465c534532b |
|
VISUAL
aHash
|
ff1f0503030103ff |
|
VISUAL
dHash
|
9efffde7cbcfbffc |
|
VISUAL
wHash
|
ff1f0507030107ff |
|
VISUAL
colorHash
|
16c00000080 |
|
VISUAL
cropResistant
|
b6fbfdc7cbcfbffc,0880dadb98985805,fff9fdc7cbcfafff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 296 techniques to evade detection by security scanners and make reverse engineering more difficult.