Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1169330607134293F40074AF6662DA34572D39005EED23742A6FE837A53B7D63EDAB28D |
|
CONTENT
ssdeep
|
768:y87hjiySK4geqCqAyKKqyG+mVureA9l0JWpi1ERPnqwEp:y87hjiySK4g1Cqtih+mxAlpi1ERPqwEp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93cfb7271a90c670 |
|
VISUAL
aHash
|
2e32fe1c05274f0f |
|
VISUAL
dHash
|
5c56a4b83d4d981d |
|
VISUAL
wHash
|
aeb67c0c0d270f0f |
|
VISUAL
colorHash
|
01380001000 |
|
VISUAL
cropResistant
|
031b134b398ce0b0,b8ac40f2f99f3a7a,0c8dc346d2723296,e1059e903203e1b1,69cca8f871b2d469,9e9e2c989ac10405,6629989e1f63cf8f,931953716d6c6c6e,47b61113361cd13d,44171b55535f4b2a,4d860f0f69693231,1769e8f8f0f0690f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.