Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB511321D0811A33459387EAB172274B16D3461CEE020D126FB51A9E6FEBF80EE2275A |
|
CONTENT
ssdeep
|
48:ppfBxm3Mi0G/I6ymaV/jQSh3X2ymCjo6ymaV/j+gymgNSZSTbmU0+hPbjhqbaZO5:pZm3MAIDtjVh3LjoDtj+TNSZSTpfvZC1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4b74d183f603366 |
|
VISUAL
aHash
|
c7ffe7e310007000 |
|
VISUAL
dHash
|
16268c0c2290e2e7 |
|
VISUAL
wHash
|
c7ffe7e7d1007000 |
|
VISUAL
colorHash
|
07008000c00 |
|
VISUAL
cropResistant
|
4616268c0ccc0e22,5b5c9c948cf432b0,8020909191908056,0c8c262fb0a2e6c3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 33 techniques to evade detection by security scanners and make reverse engineering more difficult.