Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C124F7E275319832322F91DB51572B8F72D0E2C8DBA202C586F493788BF2DD5BB5295C |
|
CONTENT
ssdeep
|
1536:e8mxNZELs9ZvXipQ7b49b7mLSUhXltLCFAk3OocaJAYNfbuYFYOaX1hxJ:e8mFO04csE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
df219c50add2a95a |
|
VISUAL
aHash
|
ff002800002cfebf |
|
VISUAL
dHash
|
7251c9c1934c7472 |
|
VISUAL
wHash
|
ff003c20003cfeff |
|
VISUAL
colorHash
|
090000001c0 |
|
VISUAL
cropResistant
|
a2a282a2e2a2a2a2,baba801a36464a00,54646c4c747772a2,a6ae808b0b79e081,a88029a958598090,72d1c9c1934c7472 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 698 techniques to evade detection by security scanners and make reverse engineering more difficult.