Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C5628521D3099E0BB1E2C104E765EA8E7655D78AD2614B49CFF5932EF0CD0B3DDA42E8 |
|
CONTENT
ssdeep
|
384:uIHYD5XUCIEA5LB4+xnHkBlXzOsbGCayu6BUFpFusIBGF6FqJI3Yp0F5F/vEuhd2:uIc5X09SqHEBztCKuWeXz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fa818575256e077a |
|
VISUAL
aHash
|
fffdedc8c8c8c080 |
|
VISUAL
dHash
|
d691992939292929 |
|
VISUAL
wHash
|
fffdddc8c8c0c080 |
|
VISUAL
colorHash
|
0b400038000 |
|
VISUAL
cropResistant
|
d691992939292929,e1d9fcf47c71c68c,0000000040400000,b139193b19292929 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 81 techniques to evade detection by security scanners and make reverse engineering more difficult.