Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10683E88A5455202D472B40E388B71FCDFB381C2FF92916D2A4B887B5B39D9F13169B4B |
|
CONTENT
ssdeep
|
768:oyWuPWuyco/uU1NH5CIs//WFLqRDLZjwqLT9H+ozl5uBzNwv18n+1X8UCEAweJBf:PDglboyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a23b0ee3e0c6c6e6 |
|
VISUAL
aHash
|
0707076767673777 |
|
VISUAL
dHash
|
8d9d8d8d8dcdedac |
|
VISUAL
wHash
|
0707074767073777 |
|
VISUAL
colorHash
|
17000e00000 |
|
VISUAL
cropResistant
|
0000000000000000,80c0c19d9de00082,36232321212121a1,7377755d98191818,e0c1c4e2c2f0fcd8,4f4d538b8f97938b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 692 techniques to evade detection by security scanners and make reverse engineering more difficult.