Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1327386A116C83525166332F7A4CF5A4F62F8B1C6D6805A84FCB0925827E1CB4B3F7B5E |
|
CONTENT
ssdeep
|
768:BG68GK+rO42rhmj9qZWKCwedslBZ2qlkHLCyumb:s68B+ruro5q0pslBZRCrCLmb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc7b4b6d12194746 |
|
VISUAL
aHash
|
00ffffdfd7ffff00 |
|
VISUAL
dHash
|
2bab1fbcb4263670 |
|
VISUAL
wHash
|
00c3ff0e12fbfb00 |
|
VISUAL
colorHash
|
00241000008 |
|
VISUAL
cropResistant
|
ab2f1fbcb4e63636,8000402020408000,506a15baca940940,009009acaaaada00,009822aa92d62100,0010101032100800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 21 techniques to evade detection by security scanners and make reverse engineering more difficult.