Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9C340B17398303B626B96D5E4A02B5972C3D14FCF83469867FC82F887C5D91FE12626 |
|
CONTENT
ssdeep
|
1536:3v/WSR4VXQH8I10hDQHqtMTvmZNKuke/BuQB/HVuq4QjZbYbHGvMNBYT/TVp7w7o:3mSR4VtYeNb9B/TVp7WtVpFA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce8c807973717365 |
|
VISUAL
aHash
|
383c3ca4a0202000 |
|
VISUAL
dHash
|
f0e0e4595554d0d8 |
|
VISUAL
wHash
|
7c3e7ef4f0907404 |
|
VISUAL
colorHash
|
30001000248 |
|
VISUAL
cropResistant
|
2884691b1b179e10,f0e0e4595554d0d8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 93 techniques to evade detection by security scanners and make reverse engineering more difficult.