Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E73E9A75148627A272773DC5B2C7B0DE26E909DCA164CA465CEC29DF2C2FB08C3578D |
|
CONTENT
ssdeep
|
768:b7SEsrF/7UtLFJbXYgU1wE0TJ5IFvfacDt7pf3TU1wKU1wOU1w2U1wqU1wLU1wbG:b7SEsrVgYqUBxPAt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bb42acfa05d22fc4 |
|
VISUAL
aHash
|
00000020008fff07 |
|
VISUAL
dHash
|
92d8c8c8c11b1bc6 |
|
VISUAL
wHash
|
002c6c7c28dfff07 |
|
VISUAL
colorHash
|
01007000000 |
|
VISUAL
cropResistant
|
94555549b6ad0dca,453b3ac30107d7d6,86d9c8c8c8d8413b,16b645d5f656b616 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 129 techniques to evade detection by security scanners and make reverse engineering more difficult.