Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A5531F30A800A93B40DBA5C5667157AA63E5D309CA130689F7F9D3E58FDFC68DE33291 |
|
CONTENT
ssdeep
|
1536:GsIxcYh2JcAJrLuBdUu9ruSIUriRzR79F:GAYh2JcAJrLuBdUu9ruSIUriRzR7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
accfd0070b7027fc |
|
VISUAL
aHash
|
ffffff000000c080 |
|
VISUAL
dHash
|
ac000f1367c69637 |
|
VISUAL
wHash
|
ffffff000101c303 |
|
VISUAL
colorHash
|
16203008040 |
|
VISUAL
cropResistant
|
e088380e1a802727,8af0b6b0db4b0024,000023c4c4240000,2f3b3367c696363d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 83 techniques to evade detection by security scanners and make reverse engineering more difficult.