Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T132137231A080693B02A753C46A71A79FB3C28346DF134F4523F8A71E9FD7E49CE25696 |
|
CONTENT
ssdeep
|
384:yOxxV23XIB+BXIB+b2lElCjEQjkuSyjdEZThlXnEX7hgblAnPX0hgqlXnEX7hgfW:yOVGtvqj3pn4MJAn7kH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a32db55aeb0d8652 |
|
VISUAL
aHash
|
010000000000ffff |
|
VISUAL
dHash
|
2b3fc6431ddcd80f |
|
VISUAL
wHash
|
0380232180efffff |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
a093e03593b380a0,d4dc1b5800000d4c,233bc6474b1ddcd8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.