Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A4330319440E82B02DB96C4A276676A63E38349C6130644FBF8C3FA5FCFC69DA37565 |
|
CONTENT
ssdeep
|
1536:ysIxJDTSSSwVVe4t+Rq7MGt0r+CqUMGq0P+3SijbfKxMjOfKx7jbfKx/SFW2Stt7:y9Dft+Rq7MGt0r+CqUMGq0P+hjbfKxMc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8bf875661a1164e7 |
|
VISUAL
aHash
|
00ffff0d00000000 |
|
VISUAL
dHash
|
d83bb3f9ede4caea |
|
VISUAL
wHash
|
0fffff1f1500200e |
|
VISUAL
colorHash
|
1a400018000 |
|
VISUAL
cropResistant
|
5ad13320fbf9f9e9,60e4e4185a5a5a5a,f9f9ade5c4caca7e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.