Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12B53E8251112696F30B389B8F4A9FB5690EAD705CA67D85C73ED83B33FC6CA4CE51284 |
|
CONTENT
ssdeep
|
768:oLxuSJdmaV7bOBOxGLiwr/To39VnxPMvMFLALTrtdvrz9RJJ+m1BjPXhF99emG3r:O8MZmeWZIAd3CAbrVxU0te13 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb4ba5a09b9baba0 |
|
VISUAL
aHash
|
b000003c3cffe7ff |
|
VISUAL
dHash
|
23106169690c960e |
|
VISUAL
wHash
|
e00000383cffe7ff |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
02202b23232b2020,6969690c00961602,4070704069696969,41104cb2b2080041 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.