Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13BB23E306A9AA03352F795D2B7361B5BB3E9C10ACD23070663F893AD0FDBD40ED49A51 |
|
CONTENT
ssdeep
|
384:4ezgEZntUr+uEuaBohB8L+bQMxUwgKzIqVsP+B3d:4QtUr+uEuaBohB8LyQggbIsP+B3d |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8313ec937bb8e432 |
|
VISUAL
aHash
|
3c00000000ffffff |
|
VISUAL
dHash
|
f0c4c4d8d9d41a27 |
|
VISUAL
wHash
|
7e20000400ffffff |
|
VISUAL
colorHash
|
030000001c0 |
|
VISUAL
cropResistant
|
d4f0ece8f0f0b296,93235d0aaa3193d2,d4cece0c31262635,c4dcd9d8d40b1927,e0d0c4c4dcd9d9d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.