Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A9833BE0F680F82349B7409EA0DED289B77E141BE70D0E50799CCAC572DA8371977AB5 |
|
CONTENT
ssdeep
|
1536:gUdaP7TF5Rh+z54NqxVmM5wj02/qRzi+zQ2N0msQw:gUlpRFVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c4647f1f1715919 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
e66874371f363632 |
|
VISUAL
wHash
|
00000083cfffdfff |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
6c74360e3a362632,900c3232b2300880,94e461616c6c3436 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 32 techniques to evade detection by security scanners and make reverse engineering more difficult.