Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D63823265048C3A15D789C58F323A1D53FDD346E5661689FEB883F8269ED78EE33284 |
|
CONTENT
ssdeep
|
768:DsIx/jKBlZkCf1EjJ/Va/M+8V3M8wzYuUf79o:DsIxfc8V88IYh79o |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e5219b5d954a97a4 |
|
VISUAL
aHash
|
00006070f2e0f8ff |
|
VISUAL
dHash
|
c686c6c686004100 |
|
VISUAL
wHash
|
004070f2f2f0fcff |
|
VISUAL
colorHash
|
0900004000b |
|
VISUAL
cropResistant
|
888cde9f9ebe3e5c,0424653434d92e00,4c67253178f2a7e6,c5f588a89aa46480,c686860260000000,d682c7c4c6860040 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 65 techniques to evade detection by security scanners and make reverse engineering more difficult.