Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T139C35CE5A9C0FD2301A341A2B046D65AF3FD052AF61D49A0F9C8C6D7B3D587A42B73E4 |
|
CONTENT
ssdeep
|
1536:iF8tc0QNtSUJl9ypwwK5wmq1+EMXinJE+BcJaS236l2OYlZzQ2N0msQw:iF8eLfYnISJOYlzVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c91616e9e9b66169 |
|
VISUAL
aHash
|
000000fffbfffffb |
|
VISUAL
dHash
|
e4e0f02313131882 |
|
VISUAL
wHash
|
000000fffbffff40 |
|
VISUAL
colorHash
|
16200038000 |
|
VISUAL
cropResistant
|
70602613131b1c13,94e060e1e9f17068,78a89d949c96e2e2,13137ccacaca3282 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.