Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13A246550F2E29C72311F81E294A4A7091192FBBBC7411FC767B146B5EBF58B9380E29D |
|
CONTENT
ssdeep
|
3072:IRnSI4HJeUfa6md8+iITH2fS/SVRwZqm7XrUEuA0JN9OWFu2G+kjOWznLV7/jSeA:ISFqvOOEvyd+n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8760787f1f7f0301 |
|
VISUAL
aHash
|
007f7f3f3f3fffff |
|
VISUAL
dHash
|
0080c060d0d020e0 |
|
VISUAL
wHash
|
00003f3f3f3f073e |
|
VISUAL
colorHash
|
06006000000 |
|
VISUAL
cropResistant
|
8000c082a2800080,a0c0d050d068a0e0,4145808280c02120,5a5bd35353db9b1b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 190 techniques to evade detection by security scanners and make reverse engineering more difficult.