Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A7238335B4459E3B2193C2D7B6B1274EF3D9D64ACA630A6A67E8832D0BC3EC0CD31955 |
|
CONTENT
ssdeep
|
384:tRAh96syAv1+I8uvJfNgez9S5dZkfdqaqBRtDRryP8NR8feh8RB9zdwJR7Meuxli:tSJ+IvO5Rt40yLH5xSvns+UX7FFosq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b94f44734e30634f |
|
VISUAL
aHash
|
00ff8f8fb9cccf7b |
|
VISUAL
dHash
|
e33a1a39339a95f3 |
|
VISUAL
wHash
|
008e8e8d99cecf79 |
|
VISUAL
colorHash
|
06200038000 |
|
VISUAL
cropResistant
|
c33a1a393b9895e3,0000066060604006 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.