Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19D131F206800DD3701CB66C8AA72537A22F58351C6130A99FAF5C7FA9BEEC6DCB37155 |
|
CONTENT
ssdeep
|
768:tdsIx/jG8DjIToD/Pa9Zf77ZcdfhUF/5IwM3Uf79F:rsIxq8DjIToD/PeZfadI5IwMI79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c33c681ee7d2386c |
|
VISUAL
aHash
|
00000c6c6c6c6c61 |
|
VISUAL
dHash
|
34d45849c9c9c8c5 |
|
VISUAL
wHash
|
80102e6c6c7c7e7f |
|
VISUAL
colorHash
|
30012000200 |
|
VISUAL
cropResistant
|
c1f0f0f8bcb4bc3c,0040029696865100,34d45849c9c9c8c5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1541 techniques to evade detection by security scanners and make reverse engineering more difficult.