Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12C33B630E9427C3F968386E17232576AB3914784CB134A4276F893F99FDAD99CF32149 |
|
CONTENT
ssdeep
|
768:16Nck9+jIkbe/RHMESvuoj6xbl407nmTvEtWF:16NWjIkI7SWoj6vCTvEtWF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
914af82f31e213e7 |
|
VISUAL
aHash
|
001c3c000600ffff |
|
VISUAL
dHash
|
b3f0d8ccce6a971c |
|
VISUAL
wHash
|
181c7c240606ffff |
|
VISUAL
colorHash
|
06c00010000 |
|
VISUAL
cropResistant
|
6160f8b8b69c9c9c,f93c38ca48d8d89a,00181816169e9e1a,b371f8c8ccce6a6a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 94 techniques to evade detection by security scanners and make reverse engineering more difficult.