Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C783F873E700263907834292FB66268AF7B9C509EB4215C3A4EEC24C4BC2E94D777797 |
|
CONTENT
ssdeep
|
1536:WgPlX5S7J9ZsNJHbPrJOrRoJHfzrJwqHu/2c7Ktcla1I7UeWn0HN5sP8ZufDMZI5:WC4J9ZsH/++/RnSEn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e747b81868e39366 |
|
VISUAL
aHash
|
0000202000ffffff |
|
VISUAL
dHash
|
b0c4ccc054340303 |
|
VISUAL
wHash
|
1c20606000ffffff |
|
VISUAL
colorHash
|
310000001c0 |
|
VISUAL
cropResistant
|
0c72496071c8720c,34dc0303030f2303,ccf0c4ccc0c06434,0021610616c08000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 27 techniques to evade detection by security scanners and make reverse engineering more difficult.