Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9831BA83519F5275AB343A720EE1403B328122B580D4D70B254FD9EB5FDC9AB06BFD9 |
|
CONTENT
ssdeep
|
1536:oTUd2rsLx4TESLwsGSMBDLw1j90+1LmjzQ:oTVTTwsiW16+1b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95eea325497f4443 |
|
VISUAL
aHash
|
021f1f1e1817072e |
|
VISUAL
dHash
|
567c3c70b2b65ed8 |
|
VISUAL
wHash
|
039f1f1e181f076e |
|
VISUAL
colorHash
|
0ee00010000 |
|
VISUAL
cropResistant
|
efbc636e6a686060,74e496f6fc60a1d1,7c7c64f01091b2e3,5a6969393cbcf2c7,c0c0c0c0c0d08272,0e0e3e6cd4d8e4f1,567c3c70b2b65ed8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.