Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F23D82862042D3E261787E8F2E5B76850BDD39DC1634158B3BC11B63BD5CE8EA1B7D8 |
|
CONTENT
ssdeep
|
768:OCJn730za2I2YmfZ4SELEzewX1tP8L5GwCp/jGLF+tfwTZ63MxL5G3MjmwnF1Bin:BJ73IZ4SeEztPqMSL4gZ68eMjmwnF1Qn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6d9292926d6d38 |
|
VISUAL
aHash
|
ffd3d1d1dfffcfff |
|
VISUAL
dHash
|
4936372738c63838 |
|
VISUAL
wHash
|
c18180809fff8f9f |
|
VISUAL
colorHash
|
07006200000 |
|
VISUAL
cropResistant
|
4936372738c63838,079f2f2f1d030a1f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 15 techniques to evade detection by security scanners and make reverse engineering more difficult.