Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BFA2B53160222BB7024B69E4BDE5778E3197C35DDA0721A547FC93E42FEEDA4B45B204 |
|
CONTENT
ssdeep
|
384:9AgK8+8tz+ATkD+2gjq+Binfu5kiA4/wAwP7D2w1IR+lFdFDIS6c4O+pGVP+QDR9:BKithk9gjdcqw/2CIR+lFdFsSJ/VlH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ecb812e74b923e38 |
|
VISUAL
aHash
|
ffffdffbf3f32300 |
|
VISUAL
dHash
|
353737322226e7f3 |
|
VISUAL
wHash
|
ffd397d3d3c30000 |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
3517373622222666,ffffffeff7737fff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 144 techniques to evade detection by security scanners and make reverse engineering more difficult.