Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15A448570F039667700D761D4D1A92FE971D1E380D6834746B2FCA36E8EE6D82E91B21E |
|
CONTENT
ssdeep
|
3072:jPwPGW1aP6rCYE4MDLiO54wdEcs0J4ZBjsX:LFgVsX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a24abf14dd3e413 |
|
VISUAL
aHash
|
1f00000000ffffff |
|
VISUAL
dHash
|
3d3d6d2474685955 |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
0b007000080 |
|
VISUAL
cropResistant
|
004d0c3d3d2d6d39,e07078f4b8fabecf,6c08495955555557,39357d6d64247474,969e4c0f17173737,1b2b252f175272b2,371f9f0f931313b3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 117 techniques to evade detection by security scanners and make reverse engineering more difficult.