Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B0334B381E3E037A32346C666591B2921E3618FDB024846A3FC43EC9FD9ED4F55295E |
|
CONTENT
ssdeep
|
768:jihTz8w/wkFww0VFNW3RhWcLbFG6eQbNK3/omhRIrBT0GLJBCa6huQ8saGuyb:jon8wYkFww0VLKRhWcLRG6eQpG/omhR3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce4c4ea2b2b6c66c |
|
VISUAL
aHash
|
001818ff7e7e7e7e |
|
VISUAL
dHash
|
ec30324ce0c0c8c0 |
|
VISUAL
wHash
|
0018007e7e7e7e7e |
|
VISUAL
colorHash
|
11007000000 |
|
VISUAL
cropResistant
|
8282c0d0d4a08282,ec30324ce0c0c8c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.