Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11623412080A4AA374153D1D5B3B6BB4B72D5C286CE530A1077F8D32E0FEBCA1ED67665 |
|
CONTENT
ssdeep
|
768:C1UUhp3++2rxra5EL6eeegeeereeeqeee6O6bsPYDPZTfCaapD:EUUhp3++29reFeeegeeereeeqeee6O6i |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e00dfa3507fa0cd3 |
|
VISUAL
aHash
|
0020706060f2ecf4 |
|
VISUAL
dHash
|
8ec6c4c1c6a4888d |
|
VISUAL
wHash
|
0270706072f6fefc |
|
VISUAL
colorHash
|
31003000002 |
|
VISUAL
cropResistant
|
692996e957656162,99c9c8a988296999,b0b5a52c4b5a5a53,8ec6c4c1c6a4888d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.