Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T155732330C1059C1B0AA755DAD23ADB69A1E58346C3130E88FBF547BA9F8ED2CDE37194 |
|
CONTENT
ssdeep
|
1536:T0ixuL8wmsC6W99VZqkAA30UogZOeN7LsIxN7+q:QiaAEUTL57r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c83fe0b7608d1acd |
|
VISUAL
aHash
|
ff00080800ffff70 |
|
VISUAL
dHash
|
b97472713939d582 |
|
VISUAL
wHash
|
ff00180c08ffff70 |
|
VISUAL
colorHash
|
1ac02000000 |
|
VISUAL
cropResistant
|
0084232b2bc42000,155555c280928088,d96c723279313939,0b0b0b0707130f2f,0048484840002020 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.