Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CFE1E5F35224876E4192C1B8EF63F090935ED0AFE2A6C9D0D79E87A914D7CD4F617920 |
|
CONTENT
ssdeep
|
96:TGmtFnyYy64wg2+3wehaBQ8VjKx3NuZkTmB0qMcSPWSic/Coa:amtg16FjywAcQSyUZxBcFL/W |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcc343364d365179 |
|
VISUAL
aHash
|
40ffff9f838383db |
|
VISUAL
dHash
|
ce281c2b2b1f0f3a |
|
VISUAL
wHash
|
00ffdf9b838383c2 |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
ce281c2b2b1f0f3a,519c948cb8969ef0,00020616060281a3,0103138b92030001,0000000000000000,dcc6e6ccccdecccc,1202322a2e2e0f00 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.