Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1121385346005693303A382C557762B0FA3C6D2C9CD631A45BBF95779AFC6E62FC1B264 |
|
CONTENT
ssdeep
|
384:DDtJ6+N0273BwI3KucLcKj7KyD0KaDKa7fQcmwcw2H8qO6IzY0qroUa87K:PtslhcyfD0DDdkDfDIzY0ZUf7K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9296686f0f2d07f1 |
|
VISUAL
aHash
|
006e6e2e2e20c1c1 |
|
VISUAL
dHash
|
338c8cccc8ca9391 |
|
VISUAL
wHash
|
01fe7e7e6e20c1c1 |
|
VISUAL
colorHash
|
00000000180 |
|
VISUAL
cropResistant
|
bce26a7eb6ece9e3,da1a398d9da5ee4f,338c8cccc8ca9391 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.