Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E5434CE47944F91225B350E720AF448573FA681F780C0D60B688EECB6AF9077617BBD9 |
|
CONTENT
ssdeep
|
768:8T0TQH7YFcUw4TzQgmMemqS8oggJNGKykg44NaMgo62uuPg2yKIM00bbyO2o800H:DjEgmMzCzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e41333135b196677 |
|
VISUAL
aHash
|
00f3f3fbf3f3f3f3 |
|
VISUAL
dHash
|
c4e6e6f6e6e6e6e6 |
|
VISUAL
wHash
|
003072f3f3f37272 |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
e4e6e6f2e6e6e6e6,52e24ed0d092b2e1,d4d4d422f0e4e4e4,86b393291b43c10f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.