Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1020252F0C6C41573174BB5C3A7923708308A5BEDDE631506C6F80B6ADBB6E68DC0BA58 |
|
CONTENT
ssdeep
|
96:SJ6509TBn9YLfqtThn2ZIeq83JJpZpscPZDYcG2dl5TFlqZMrOtgftAgpu:SJ629Txt2b3PpZpsohYcz1Jpu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9f37879d2d2121 |
|
VISUAL
aHash
|
bc3c001818180000 |
|
VISUAL
dHash
|
6969163232b03000 |
|
VISUAL
wHash
|
bdfc183c18180000 |
|
VISUAL
colorHash
|
38200030001 |
|
VISUAL
cropResistant
|
6969163232b03000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 25 techniques to evade detection by security scanners and make reverse engineering more difficult.