Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1832374325292293D256787F675A0B36980EEC31EC497D62A53FD53711FC6CD2EEB2280 |
|
CONTENT
ssdeep
|
384:PqlBqmNSuG2Y7J7rpmMIZ7NGUiAMFQ0RxYsFxRWIBahiPoZBK1uRRwMYYT:irqh/Bah3w4T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc987332c633b3cc |
|
VISUAL
aHash
|
0018181818000070 |
|
VISUAL
dHash
|
8c32b230328ca4ca |
|
VISUAL
wHash
|
5a183c3c3c7c7c72 |
|
VISUAL
colorHash
|
38000000c00 |
|
VISUAL
cropResistant
|
8285da2d2da680a2,8c32b230328ca4ca |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.