Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T107733BF5AE44F92345F340A7718B954BB279180FF50D8990B508CBCAB3F94B7126B6A2 |
|
CONTENT
ssdeep
|
768:5MT0TQH7c5Y7KyPE417Tycpfbf09EVzc+b42NB2jIGrTnzq8QE12OlDlGYQZ/y:5AK6vRG9QzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9236e539c5c6b591 |
|
VISUAL
aHash
|
0604243c0c0c287e |
|
VISUAL
dHash
|
8c0deced7818c8e4 |
|
VISUAL
wHash
|
ff043c7c0c0c28ff |
|
VISUAL
colorHash
|
30600010000 |
|
VISUAL
cropResistant
|
cc4a0c9a9bd9dad2,b3b3b66464c6c3c3,f0c8cc8c24262626,8c0deced7818c8e4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.