Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C2226534A5059E3B50D7C3E1A365377B32E0428AED5B5315A7FA83AC8FCAC86DD39105 |
|
CONTENT
ssdeep
|
96:ghc5qfFvfx2mi9R2tEgE/E//7A7oLI+sHjnm9yzMfrsfS26f0vnX97yFqDkE8qDq:gqqisEaFsHj/YGS/f0v9GFWk7qDUDx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b89b67c3ccc71838 |
|
VISUAL
aHash
|
f98f8fdf8fdfc3c3 |
|
VISUAL
dHash
|
63183a383c301737 |
|
VISUAL
wHash
|
998f8f8f878f8181 |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
63183a383c301737 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.