Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C4832BA43A1DF56659B343A710DF1103B378561B580D4D20A310FDAEB6BCCAAA077FDA |
|
CONTENT
ssdeep
|
1536:EWGBklbz01vWoNhh84/thBXRjaPndf8f/9u:EHBklbpym4/TBd5H4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88485d2fa2f2a737 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
1132b0007f7f0040 |
|
VISUAL
wHash
|
000000ff01bfffff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
e8b1807f6f000000,1009113030303288,ffffffffffffffff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.