Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10A03C7F383C05A3211B182C992616E0DC7C4A1889F4746D7EBAB477EF1C8999F131BE9 |
|
CONTENT
ssdeep
|
384:l/c0nY2DX6eEA8Ll6b5ub+2EJuRYpYU8l3oTr3RhyMocJE4ZA:lXx8LA9ut6rBEiJ7S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
acb414b69795b4a5 |
|
VISUAL
aHash
|
5701c3fdb9f03818 |
|
VISUAL
dHash
|
94a923636321f0d0 |
|
VISUAL
wHash
|
5f0183fdbdb03838 |
|
VISUAL
colorHash
|
0f600000001 |
|
VISUAL
cropResistant
|
911191d9c9d91099,dedc8c9862e1e939,e0d0e8e2ca0e17c4,94a923636321f0d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.