Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12BA3DE234269752B4437C7C130695B3BE1A6D99FFAE70A000EECC7F72AF9C90741A169 |
|
CONTENT
ssdeep
|
1536:hStpR4nXBKpSpFl26vFSZtdyjObGjh3IJvJy:UUMby6bGdAvJy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92076d13930f6f2d |
|
VISUAL
aHash
|
001f033e2e0f01e7 |
|
VISUAL
dHash
|
ddbf76fcdcdcf30f |
|
VISUAL
wHash
|
000f033f7f0f01ff |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fda77cdcdcbdf70f,dcbd67fcdcdcb777,536b8c6b63dc5555,2e470513161c3424,cc110c32320c0121 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.