Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C912D7339101D6290FD7435CFAE1E68DD36AC185E33899C662C9115F3AC4FE18572BE9 |
|
CONTENT
ssdeep
|
192:6n2ondnF5KnpU3LG2y4j6bfxNricY4EDOkfMmUU8VCoyp:25zGZ4j+7iNDOkfMmUFCoyp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba3ac56c6cc59392 |
|
VISUAL
aHash
|
8181858185cfffff |
|
VISUAL
dHash
|
23191d1d1d1b241e |
|
VISUAL
wHash
|
81818581858dffff |
|
VISUAL
colorHash
|
17c00010000 |
|
VISUAL
cropResistant
|
23191d1d1d1b241e,f8b4333b12183eb8,c0b89c9e9e9e9e5c,465eaf2b1b0327bc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.