Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11362A7208586693B12B213804B86F71FEA84E1C0E2374EDDD5FD8B8AC6C9DE8CD75259 |
|
CONTENT
ssdeep
|
384:E44C4r5mQDcF9dnFU8ycSgWFUogwxTTU7Lis:E44WQibFUWSgwUoFxTwas |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
999d66259d343d31 |
|
VISUAL
aHash
|
383c181818183c3c |
|
VISUAL
dHash
|
e271b2b2b2b2f0e8 |
|
VISUAL
wHash
|
7e3c183838187e7e |
|
VISUAL
colorHash
|
30200018000 |
|
VISUAL
cropResistant
|
f378744cb9795ccc,4948727b79134bca,e271b2b2b2b2f0e8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.