Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T172D240B09181E9272167D4D8E679DB1F73C5828EC783078153F893B96FCACA0FD12659 |
|
CONTENT
ssdeep
|
384:taUQiJro6XSosJfoRjToFCUoM98LW55+7KMjUcEUXkDWUt:taUQiYYjUwdy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd61672660bc34ed |
|
VISUAL
aHash
|
0038181c381c3c38 |
|
VISUAL
dHash
|
f6f0723272707173 |
|
VISUAL
wHash
|
103c3c3c3c3cbdbc |
|
VISUAL
colorHash
|
32201008000 |
|
VISUAL
cropResistant
|
8870b0e0b4e4e4b4,a6d0da8010606580,e0e088aaaaaaabe4,6669294c40604060,f6f0723272707173 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.