Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12BB2CA73311D743B12A785C9E391720CD2D2D687CB455898B3E9C36C87F2DB0BA57A68 |
|
CONTENT
ssdeep
|
384:FDCnCf3zrhb8o/F/kmro1eg7eMGeKxpwe4deckeEeeAVO48oag:d/F/kMpoO4x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f2728f8e8ca18d8e |
|
VISUAL
aHash
|
efc0c0c0ffffffff |
|
VISUAL
dHash
|
9c8d989c95b24032 |
|
VISUAL
wHash
|
c0c0c0c01fffffc2 |
|
VISUAL
colorHash
|
06000038200 |
|
VISUAL
cropResistant
|
9c8d989c95b24032,6f7f9f9fbf7f9f87,06265aa363e2a2aa |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 25 techniques to evade detection by security scanners and make reverse engineering more difficult.