Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14AD3B4F2C370A872215B51F8EA356ADAB685A9A8CF93454453FCDB68CBD3C84DF1250C |
|
CONTENT
ssdeep
|
768:vzRkn8ecjEgqPsEBNx5r75MKSFa3Y0i4m0gcc9N7iLH166S3am4naW:vzR+SEgqPsETxJ76KSFao2gc0ir16mnj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a33f24ce56ae429 |
|
VISUAL
aHash
|
bf000c0e181919ff |
|
VISUAL
dHash
|
7858587c72f1f171 |
|
VISUAL
wHash
|
ff040c0e1d1919ff |
|
VISUAL
colorHash
|
0b401030000 |
|
VISUAL
cropResistant
|
7858587c72f1f171,ecf8f8f0f0f0f0f2,78d8d8fcf2f3f1f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.