Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D9A3FCB096441EB3E213E391EF50B3D701F970AD9EB24110A8B8C1C9DFDAC6AA5395D7 |
|
CONTENT
ssdeep
|
768:QqR9m/44N44ETuZDn6P6e8DbGt5TAsHrfrfchF6I4amME:+44N44fF6wQ5TAkrfrU/h4ME |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94e44b78315a676b |
|
VISUAL
aHash
|
02b6360606061c2e |
|
VISUAL
dHash
|
9e26e6be9eb4396a |
|
VISUAL
wHash
|
c6f67e0e06061e3e |
|
VISUAL
colorHash
|
01002000180 |
|
VISUAL
cropResistant
|
f0dbfbeaf6adcfda,ead4abbebffaf8f9,73328dc9cf2eba8b,926079698ccccccc,a2d5c8cc67f0e8e8,9e26e6be9eb4396a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 155 techniques to evade detection by security scanners and make reverse engineering more difficult.