Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D0B34B243248757FA9B303E770E67316B27C520BD40B4D14B364F8E6AB69C9AA437BD4 |
|
CONTENT
ssdeep
|
1536:uc5OtyA/tXlWL2agDwZvd/lPW5+amxhipe6Ir7YxSnGnEnCd2r:uc51g0rk5+nwpe77JUd2r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed39924646d21f69 |
|
VISUAL
aHash
|
208f8b93f1b3ffff |
|
VISUAL
dHash
|
e11b33332723880e |
|
VISUAL
wHash
|
008b8181d193ffff |
|
VISUAL
colorHash
|
06001600080 |
|
VISUAL
cropResistant
|
e11b33332723880e,00000432b2b21a04,004b96f609904000,5a4b195c585c5e72 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.