Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1575383729554243B422794C8E1687E28D2C7A20ECF534E45A7FC47E9CBD9EF0B86239D |
|
CONTENT
ssdeep
|
1536:wgWTegCJyCwVVlvha8adbKI1jf5qHH73x85k7+xWBi673kScM3AlSyC:VWTegCMCwVVlvha8ad+I1jf5qHH73xEO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92e99296e99c3947 |
|
VISUAL
aHash
|
ff3c0000281e3e2c |
|
VISUAL
dHash
|
71e8f0f0d0fcece8 |
|
VISUAL
wHash
|
ff1810007e3e3e3e |
|
VISUAL
colorHash
|
30000030000 |
|
VISUAL
cropResistant
|
717184033333c000,dcdad2f62dcadcdc,f171f1d4d171f1f1,e8c033d0c8fce8d8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 290 techniques to evade detection by security scanners and make reverse engineering more difficult.