Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T148D360D55628038CA057CA7DEF2FFE05131FB5AABA544A80294EC26C96CF8D2F71752C |
|
CONTENT
ssdeep
|
1536:NU0RQ7Hg/ezS8a762lFsR8MLqcpVFsR8MLqcMP0:u0RQ7HSwaUaB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8c8a2b79537b534 |
|
VISUAL
aHash
|
7979793838ff00ff |
|
VISUAL
dHash
|
d1d1d1f3f0cc3300 |
|
VISUAL
wHash
|
7979383800ff00ff |
|
VISUAL
colorHash
|
06e00010000 |
|
VISUAL
cropResistant
|
d1d1d1f3f3f1d0cc,0000000000000000,616163633b3b737a,3e76767676657272,0f0f1f1f3e3e3e3f,0008101010100800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 149 techniques to evade detection by security scanners and make reverse engineering more difficult.