Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T124532072A544EC3342DBA5D4A237525A62FD8385D9470298FBF4C3AC4BDACDADE3B410 |
|
CONTENT
ssdeep
|
768:AuUf74Nmet3FG1cfFpZ1ZHFX0Di5FX0DiFd4fcGVXkPAxxBXPELExVLEPCLEEmE1:07ymq+2AIIBYolsIxBYXm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9644ed39f2316b0d |
|
VISUAL
aHash
|
00363666060c3efd |
|
VISUAL
dHash
|
8cc4e4ccdc38dc55 |
|
VISUAL
wHash
|
003e76660e0c3eff |
|
VISUAL
colorHash
|
38000c10000 |
|
VISUAL
cropResistant
|
8cc4e4ccdc38dc55 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 68 techniques to evade detection by security scanners and make reverse engineering more difficult.