Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154B34B743648B93A5AB343D3509F22137279521F940F4C20B364EDAE62ADC8BA477FD9 |
|
CONTENT
ssdeep
|
1536:p3wuXgfbsQJo2h2wV92949tVPTMn5UCCDuFaX238B:XXkXMA2i9nYC4aX3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f8324b1acacb92e9 |
|
VISUAL
aHash
|
0000c3ffc3fffbfb |
|
VISUAL
dHash
|
691696bc963c2232 |
|
VISUAL
wHash
|
0000c7c7c3cfdbdb |
|
VISUAL
colorHash
|
070000101c0 |
|
VISUAL
cropResistant
|
00696921002120c2,96963c9e36282232,00c021232323c000,0040039393408100 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.