Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F44D9E4D33453FC5C5A87DEB6346424751E10EEBAD28E7882A8CE5066D3DD8CE89CC6 |
|
CONTENT
ssdeep
|
1536:Z951vSOwLS6LFGHB1tNbg6mYds6PFyZQKc6twc0lpZIRgjfX6zROPmiRTpjO7RmM:0ZrQZKSiNN8UCySSjqjq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93a56be01679964b |
|
VISUAL
aHash
|
007fff3fffff0000 |
|
VISUAL
dHash
|
c9c7dee8e8aa9b69 |
|
VISUAL
wHash
|
00676f3ffffe0000 |
|
VISUAL
colorHash
|
0720001a000 |
|
VISUAL
cropResistant
|
c9c7dee8e8aa9b69,e5cc8cac2c2d9f9f,9c9e86060703c179 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.