Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED8232309044697B028383C9EA319B2FB6D39345CA270B1663F5836F5FDFD86CD256A6 |
|
CONTENT
ssdeep
|
384:40jnT6kFDYC8z1KwA+i1lRLPbAMd4V4/7:40P6kBYC8zzA+ixTAMd4Gj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e5549a6bd4a4d60e |
|
VISUAL
aHash
|
f0e333622060f3ff |
|
VISUAL
dHash
|
8296e6c646cfc3c5 |
|
VISUAL
wHash
|
f0e332622060f3ff |
|
VISUAL
colorHash
|
12201000180 |
|
VISUAL
cropResistant
|
b2baa2aeaea2aa82,c4a2a28864daca64,0105010102000100,8296e6c6c6cfc3c5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 99 techniques to evade detection by security scanners and make reverse engineering more difficult.