Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C702B67446C45B2FAA47C686B1BAE21EA14279C6D4C70DCFF0B02BA5D98CED9D4032D9 |
|
CONTENT
ssdeep
|
96:lPVbrFFeDDLl5f2MNTu4Y228akbgoRbeALQ6rFkROmL9LZ:TrF4ZpNTu4RJakUMbeALQ6rFk4mL9LZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9313cc6273adec31 |
|
VISUAL
aHash
|
fc0c3f0c04f7ffff |
|
VISUAL
dHash
|
615d7e595d658a40 |
|
VISUAL
wHash
|
bc0c080c04f4ffff |
|
VISUAL
colorHash
|
07200188000 |
|
VISUAL
cropResistant
|
615d7e595d658a40,2c936d1749231b0f,8e0701000103078e,8e27294001430f26 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.