Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F5328AB18179D87313E382D5B6B65B4B7281830ADB230B4663FC8B5E6BDFD54EC1A160 |
|
CONTENT
ssdeep
|
192:0Yvn1Vr+mOhhumlqviSs9cEC0TGy6GceMd7McvIDt:Titht6iLJG7IMhMcgDt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8a5d2cf4327383b3 |
|
VISUAL
aHash
|
18183c3c3c3c0001 |
|
VISUAL
dHash
|
3272794949696b0b |
|
VISUAL
wHash
|
38383c3cbdbfa501 |
|
VISUAL
colorHash
|
06000030000 |
|
VISUAL
cropResistant
|
c9c9f031ab1b47e0,a8a89cb2fe8eb29b,3272794949696b0b,f08d25a525351b1b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.