Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A674D422E780636BA047EBECB78EA670B13EAD5DFFC3CA4752D44516660ACD81512FC4 |
|
CONTENT
ssdeep
|
1536:wDV73arXMvnEzfqSq/bqK1GdDVgXarXMHnEzfqSqR0bq61oxDHl1er2fqNZf65zx:cJXQO8NZf09 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edcd3292c66dc446 |
|
VISUAL
aHash
|
fedbd3f3fbff81c3 |
|
VISUAL
dHash
|
c8323736272b0b27 |
|
VISUAL
wHash
|
7e8b9193f7c38181 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
c8323736272b0b27,ec723d0e87c7c1d0,996c76360b0349c8,2130d3d3d3932c2d,4541410100000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.