Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C37309E0B241FE2325B340EB605ED185B276582BF44D0D60B2C8DEC9A6FA437256B7F5 |
|
CONTENT
ssdeep
|
768:pT0TQH7YFcUIngqYT/XJNVVWv95RrP33c6/jbVR55CrWaiM4ww/KOyaEwIIfl1JK:gIngqSCzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96edc38d9493e498 |
|
VISUAL
aHash
|
ff00000416700c04 |
|
VISUAL
dHash
|
5216473d34c5194d |
|
VISUAL
wHash
|
ff80101607750f07 |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
5196864249910200,f8f8a68eecf9f078,b1bc3c34745299b9,164cbc70c0c1719c,1982aab2b28aa201,1615c53534cd194d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.