Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E1E111E0C454EE37475386D9ABB16B0B73D1C359CB460944D3F883AB5BCACA0CA655A8 |
|
CONTENT
ssdeep
|
96:TkqSzeFvMSfuSTCctu8sISS8ct7HegDwvF5QexXeHFqEe1Xvz/J9Y4YfGJ:QqSzeFdjWck8sWtegyIszRzTfuA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dab525cb32ccabc0 |
|
VISUAL
aHash
|
c282dadcfcfcf8c0 |
|
VISUAL
dHash
|
061696b19979218d |
|
VISUAL
wHash
|
c282dadcfcf8f840 |
|
VISUAL
colorHash
|
07600030000 |
|
VISUAL
cropResistant
|
061696b19979218d,78603f1f1f87c3c1,43460c8c80a0a183,097e777e7ffdfffd,4f8f274343636101,1894d99387871323 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.