Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T175D23F746441FA37818BA3D1A7709B6BB3D0A2D5DA63070923FCA39C9FD7D58EC12A11 |
|
CONTENT
ssdeep
|
384:qvM447p81AYP8C135iw65AfJmz+U+41nnh+xnUxpTGgXZ6iPxxJSyo86:qk44UAW8Cqd1n8+LQWmL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac6ec1c3931e9e92 |
|
VISUAL
aHash
|
f9f1939d9db5f1ff |
|
VISUAL
dHash
|
41333535356563d2 |
|
VISUAL
wHash
|
bdd19185859530fe |
|
VISUAL
colorHash
|
07c00010000 |
|
VISUAL
cropResistant
|
41333535356563d2,4545717147d480a2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.