Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E03DB30A804E93701DB99C85632576A62FA8346C9131689FAF5C7F91FEFD28CE73215 |
|
CONTENT
ssdeep
|
384:0DUsJO5xVZjqTSH4SBDgqwrsrz9e1HGSq+imb68C9A9kDmroUa87y:0DUsIx/jv4ScrUkVqmbUUf7y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f3ae04285ef5c94 |
|
VISUAL
aHash
|
ff8180000000ffff |
|
VISUAL
dHash
|
ab2b2e76786849b6 |
|
VISUAL
wHash
|
ff8b87000000ffff |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
248b2b2e2e7244f8,4445b6aa1a3696a7,49458020c439b2a6,f3f7e37373737333,252313979f9fb32b,2b2b2e725468b849 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 90 techniques to evade detection by security scanners and make reverse engineering more difficult.