Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17B0253E2D0949836076642C5F7B53F6F77A1C285CF060A5413F4532F9BCBE91C6135AA |
|
CONTENT
ssdeep
|
96:TIz3JwLzYh7MS/tVSTA7Zt75xhUSPRttkQ8v67x9R/dtmMTUMcCtmMTzIKBfTRlX:TLzYhhi8nf/P8iddYMgEYM3IKBftlU8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a3f3085ca6778378 |
|
VISUAL
aHash
|
e7ffe7e7e7ff007f |
|
VISUAL
dHash
|
0d0c4d4d0c4810c0 |
|
VISUAL
wHash
|
e7e7e7c3c300003f |
|
VISUAL
colorHash
|
06000180000 |
|
VISUAL
cropResistant
|
0d040c4c4d0f0a0c,000000c000d0d0d0,3839395978397a76,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.