Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A6F32CB43695F4930AB747A3806F1002F3385D3B140D5960A395EDEE727999EA0F3F9A |
|
CONTENT
ssdeep
|
1536:mAZ38/5TGdiOo7a6Ih6PgRwT/x2t8qL1g/cF7yCRFX6CzbxF9sPaPJuBq/2Y7v1x:mPOo7SQ4Ra/8cKbCq7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b333cc8c8c6633b3 |
|
VISUAL
aHash
|
ffe7e7c7efc3c3ff |
|
VISUAL
dHash
|
000e4d0e180e0e00 |
|
VISUAL
wHash
|
ffc3c3c30303033f |
|
VISUAL
colorHash
|
07002000180 |
|
VISUAL
cropResistant
|
000e4d0e180e0e00,0677830373939786 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.