Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2331D306850DD3741CB56C8A672177A22F58351CA130A89FAF8C7BA9BEEC69CB37055 |
|
CONTENT
ssdeep
|
1536:zBsIxmjIagBqZfZj7+66sbrBl4QHK93479F:zBpBYa47T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c6d6390688dcf9c |
|
VISUAL
aHash
|
0000383c1e1e1e00 |
|
VISUAL
dHash
|
b5b06070b47c7035 |
|
VISUAL
wHash
|
107c3e3e3e3e3e01 |
|
VISUAL
colorHash
|
3a007000040 |
|
VISUAL
cropResistant
|
a4a4a480c8f870c0,b5b06070b47c7035 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1545 techniques to evade detection by security scanners and make reverse engineering more difficult.