Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DEA3DE238219752B4437C2C1307A6B7BD1A6998FFAE70A410EDCC7FA2BF9C90745A51D |
|
CONTENT
ssdeep
|
768:EZoTUtpR4nXF6YjOpSpFlTC6rrWWYVmqjZRKNYEe:EZltpR4nXBKpSpFl26v7YVmq9RKXe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d26f6c81928cacbd |
|
VISUAL
aHash
|
c1c0e03e2e70c0c1 |
|
VISUAL
dHash
|
0385446ccca0800f |
|
VISUAL
wHash
|
fbe0b03e2e7c40e1 |
|
VISUAL
colorHash
|
110000080c0 |
|
VISUAL
cropResistant
|
03002b2b2b2b2321,9200806060c00092,96008060608000e2,8200a06060800042,8000a0a0a0800008,96b6b64616ccc636,0384646ccca0800f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.