Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F243B621A885EC2601DF99C89573527621FA8385C62316C8FEB5C3FA57AFC7DDA33504 |
|
CONTENT
ssdeep
|
768:stRR5cms2R/jf2R/jscjcz/OKHGegX9K7PY/ZUf7TUf7N:wRR5Js2RL2R4cjMHGegX9K7PYW7s7N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c288b7b49bc8ed83 |
|
VISUAL
aHash
|
ff24707c7c00003c |
|
VISUAL
dHash
|
3cedc3f1e9accc70 |
|
VISUAL
wHash
|
ff74787c7c00243c |
|
VISUAL
colorHash
|
0a0000c0280 |
|
VISUAL
cropResistant
|
0000000000000000,acaea1b5b1914e6c,4c9a929292929298,416aba2f2f9b9810,5a4a2ca4b594535b,ede5d3f1e98ccc70 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.