Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1716393706104CC3352938AEDBBB1631EB1F2931ACB8359C8B6E493E95BDBCE5CD21165 |
|
CONTENT
ssdeep
|
1536:5GPzib19De4FqXXzib19De4Fqhzmhyy7vsmMiB0:r+iB0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb3030753296cf9e |
|
VISUAL
aHash
|
00c1ff3c3c3c3c3c |
|
VISUAL
dHash
|
9e96416969616969 |
|
VISUAL
wHash
|
00c3ff3c3c3c3c3c |
|
VISUAL
colorHash
|
06c00008000 |
|
VISUAL
cropResistant
|
9e96416969616969 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 131 techniques to evade detection by security scanners and make reverse engineering more difficult.