Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D963D9139184273F429323C9B634679DB396E05C9A1D0E219D9ACF8C1BE6C74EC7E29D |
|
CONTENT
ssdeep
|
1536:GII5/TTpX1OJ0rW/gJKb8CmA+Syvooqmk+7:S/TTpX1OEJKb8C+SyoZmk+7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91669e789d69c692 |
|
VISUAL
aHash
|
063664087e7c083e |
|
VISUAL
dHash
|
9cccccd2d0d0d8f8 |
|
VISUAL
wHash
|
0e76640a7e7c0a7e |
|
VISUAL
colorHash
|
38003010000 |
|
VISUAL
cropResistant
|
60c68692b33471b1,d8e88cf0c05933be,0c0cac6aaeae3637,32f0cccde6e662ec,f0c686938eced098,9cccccd2d0d0d8f8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5043 techniques to evade detection by security scanners and make reverse engineering more difficult.