Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F43E9B24044D63722D3E3E88E28BB0FB6DCD148CD7545A89AD7C68E26C5F609D7534E |
|
CONTENT
ssdeep
|
768:vR7DFgLF+/e3Y1wXg3XLmDhRJ9q8xjCHJnq48pEtut96q:g+zm9RJ9qRq1Gq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d20ff08f29f006fa |
|
VISUAL
aHash
|
000000003c7cfce0 |
|
VISUAL
dHash
|
c4c1e8f869c89094 |
|
VISUAL
wHash
|
047030187cfefcee |
|
VISUAL
colorHash
|
11007000000 |
|
VISUAL
cropResistant
|
f400415555550152,8200415555414082,6a4cccca4ac9c94d,c4c1e8f869c89094 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 182 techniques to evade detection by security scanners and make reverse engineering more difficult.