Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E9C254B30099693713A6D1C2A6347E6AF382454BCE561A40E3F893DDFBD2F51C9B2468 |
|
CONTENT
ssdeep
|
384:qnYnc+6uUoLDDNNlNIOkri+MjBirjotE13uev0u6G:a+JkbqBiPotXev0uD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7e9b6e43982c5a1 |
|
VISUAL
aHash
|
633c3c3c003c3c34 |
|
VISUAL
dHash
|
c4d0d0d0c8e4e4ec |
|
VISUAL
wHash
|
ff3c3c3c007c3c34 |
|
VISUAL
colorHash
|
38001018000 |
|
VISUAL
cropResistant
|
a2888e8e8eda969e,1a3b33ba33521333,a9e1810616161799,b830763819c9d9e8,1a2a1c1626a6e763,d496172c466324c2,14b0303b9f968ed4,c4d0d0d0c8e4e4ec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 951 techniques to evade detection by security scanners and make reverse engineering more difficult.