Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12CA2AA21B500BC26C1138EEF9564DA15B74DF329CE1A17C2F3844B3AABA5C70BDB7568 |
|
CONTENT
ssdeep
|
384:gd7bQ3jO66UK4vLLgyByPtbIGCjwbsSnq6zEXLke0:gBbQ3jO0X5BltjwbsSnq9bke0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6666633998a8b66 |
|
VISUAL
aHash
|
e3c3e3ffe7e7e7ff |
|
VISUAL
dHash
|
4c4e4c080c4c4d00 |
|
VISUAL
wHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07400018000 |
|
VISUAL
cropResistant
|
4c4e4c080c4c4d00,693929696929a96a,78387878781c1581,7569a92166967589 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 320 techniques to evade detection by security scanners and make reverse engineering more difficult.