Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13C7351A46982E93F91CB9AD561720379A2E68700CB5342C5FAE4C7F98BCEC5DDE33144 |
|
CONTENT
ssdeep
|
1536:QJsIxHZw+C+DPxKJYZYDY+Y6Ytj0VS1PGDT4jIia6np79F:sbZPpwwWHjEj0VS1PGDqDp7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b86c93c738c69369 |
|
VISUAL
aHash
|
ffc38383c3ffffcf |
|
VISUAL
dHash
|
201f3b3f1fc09a1a |
|
VISUAL
wHash
|
df81818181df5f8e |
|
VISUAL
colorHash
|
06000000180 |
|
VISUAL
cropResistant
|
201f3b3f1fc09a1a,ee9a79edafb297ff,71737272f3f37272 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 73 techniques to evade detection by security scanners and make reverse engineering more difficult.