Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FDF13422A2546A1963C942A9FE32C7DBB74146D1C3090FB95BB4832FF85D2E0893B5DD |
|
CONTENT
ssdeep
|
192:V/olr+I3UITS9UVJTcOJKxfYPpt54U+AqPFy+LX:FUSd0S9UVuPA8X |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac1303e4f3ec662b |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
fcf0fb9e1e262618 |
|
VISUAL
wHash
|
000000dfcff3d3ff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
80808080a000ffff,311e1e262626261a,ffbff4d4fbf1ffff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 47 techniques to evade detection by security scanners and make reverse engineering more difficult.