Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E4933BE0A284FC2205B740D5B09EE3C5F3B6022AFA5C0EA0759DCAD673DA87706A7575 |
|
CONTENT
ssdeep
|
1536:xpotRlNvLzDwe6n0M3kYOsqwvHjzQ2N0msQw:HjvpVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4aa5427f31329d5 |
|
VISUAL
aHash
|
f7ffd7e7f70000f0 |
|
VISUAL
dHash
|
8627378d0f0fa8a4 |
|
VISUAL
wHash
|
f7f7d7e7e3000040 |
|
VISUAL
colorHash
|
08e00010000 |
|
VISUAL
cropResistant
|
b9bf7fbf9f7f3f3f,0206066661000404,1388ec13909dc686,87a170f88ae7e3c3,0080a4808ecc8e80,38172e4f26d4cc35,f1ccce96c6ccccc6,f8cadbb333773e1e,80829acccc8a9282,8627378d0f0fa8a4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.