Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF739331A5475A3B4A87E1D1AB346B9EB2C2C34BC7930D087BF5831ADF86E14ED1A570 |
|
CONTENT
ssdeep
|
1536:1jEoPAbVBs2fu7QuGMvYKI7FE3+nUjIbJmCRzCZIDT/YU6MF:1jEoSUU6W |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
da28a593f8ea96a8 |
|
VISUAL
aHash
|
ff000000003cffff |
|
VISUAL
dHash
|
33b2332131c46432 |
|
VISUAL
wHash
|
ff001800007effff |
|
VISUAL
colorHash
|
0fe00000040 |
|
VISUAL
cropResistant
|
0104612b6b2100b7,c94644c9c9353470,137b09cccc9dc464,c4c4e427272b9ab2,b2e3333129336cc4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 146 techniques to evade detection by security scanners and make reverse engineering more difficult.