Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C0139696310866E5C2F34ED8A81065906046EF4EC9728770C2F84E7667E39B5B78CF7E |
|
CONTENT
ssdeep
|
768:XzHuWmaylDRxDMPJ6JsqYJ3JF0Ob+whs4jY7yUjJoHb4H:XzHuW03bkM7LH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e8daa1c1e5a5d296 |
|
VISUAL
aHash
|
ffd5dc90f8180303 |
|
VISUAL
dHash
|
aba9293321f30676 |
|
VISUAL
wHash
|
ffdddc90f8180303 |
|
VISUAL
colorHash
|
32c01008000 |
|
VISUAL
cropResistant
|
abababa929293931,08f8e828d0d8d880,94b484de6ab37938,8dc5c4e7c76a6a68,c9c8b0b088b18e8c,aba92923a1f30676 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.