Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F2383322944DC7600DBAAC85572032662F95385E653068AFAF8CBF95BEFC6CDD33425 |
|
CONTENT
ssdeep
|
768:hKF4s3QZELk+Cu6sIx/jDvuegP6kkhL4vUf7x:hM4x+CJsIxHvuegCRF4A7x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e86293b94db22cd6 |
|
VISUAL
aHash
|
ebfbd0d0f0d1ffff |
|
VISUAL
dHash
|
1253a5a393b79896 |
|
VISUAL
wHash
|
c3f810d0d0c0cfff |
|
VISUAL
colorHash
|
07200030200 |
|
VISUAL
cropResistant
|
1253a5a393b79896,0f07070b0b4b3b07,95981a3b33333332 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.