Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF726372945D993B13A3C7D9F2F1AA4EF7818189C982014AD1FBE35C2FE2DB1ED16205 |
|
CONTENT
ssdeep
|
384:vjFegcRsFCyemtffntntFtyytx7totBtEtuR5RZcR5RjRNdtJpTtdtPIBRTx:vjFegcEntXntntFtyytx7totBtEtuXTv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e71e9863a16996b1 |
|
VISUAL
aHash
|
809e9ee1e3e3e1ff |
|
VISUAL
dHash
|
33342c064f4f430e |
|
VISUAL
wHash
|
809c88e0e3e3e1ff |
|
VISUAL
colorHash
|
06000000180 |
|
VISUAL
cropResistant
|
33342c064f4f430e,23d8517151338e4d,bd9aa4ad87acb6d6,f2a6cdc6ce65969a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.