Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T168B3CE25C953132241D3C3FCAF61DA56918143389526A17872BE86B7BF8FCECC9A15E3 |
|
CONTENT
ssdeep
|
768:Y35KylCpF/Z2Nq+qpB4GoJouPoGoAoDogokoeozxo+olo6oQoSoVocoOoP5XJmTu:Y35FlmF/ZRB456XJ2yg8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d398ec6cc0d3d16c |
|
VISUAL
aHash
|
ff1f3c7c00000000 |
|
VISUAL
dHash
|
0075d8d845d8c4c4 |
|
VISUAL
wHash
|
ff3e7e7e24406060 |
|
VISUAL
colorHash
|
38006000008 |
|
VISUAL
cropResistant
|
0000002020000000,ffffffffffffffff,fef2d0ccd7e67030,0075d8d845d8c4c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 102 techniques to evade detection by security scanners and make reverse engineering more difficult.