Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19AF11FF0D440ED3B475386D9A7B56B0B77A1C349CB430A4593F893AB6BCACA0CE21599 |
|
CONTENT
ssdeep
|
192:QPnbzD715lt8iTnBS+mYMc6Z+BzZYMjacq0:QXnf1LBS+PMc60oMjacq0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c93333293b38c |
|
VISUAL
aHash
|
c3d3d3d3d3c3ffff |
|
VISUAL
dHash
|
3733333333370022 |
|
VISUAL
wHash
|
8181918191c3ffff |
|
VISUAL
colorHash
|
06000e00000 |
|
VISUAL
cropResistant
|
3733333333370022,53dae0e2ce8c8aba,6262736363626262 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.