Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CF13EDA2DA012C97622746C0B02A17BD3891556F8F43465842FA8FF9F3FACF1652D7D8 |
|
CONTENT
ssdeep
|
384:pc7IAlcX9PitiItmbitiCRb7aitifOGitit+2itiNE6:pqIAK9606mG0Ap0Wh0wR0q6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
afb7970c64e90c70 |
|
VISUAL
aHash
|
bfbfbfa300088800 |
|
VISUAL
dHash
|
6f4d4b47377b1bcb |
|
VISUAL
wHash
|
bfbfbfb700198800 |
|
VISUAL
colorHash
|
11c00010000 |
|
VISUAL
cropResistant
|
0003a0c020f31840,de9bbbbbbbbbafaf,f1c0700664ec464c,4c8c8c8e333b1a1b,0090e0c88d858706,b38fa5ccb8313326,9aa327272d4e968e,6f4d4b47377b1bcb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.