Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C2234BB26732B4B843DA91DEE7382E06B2C2989DF9C74554F1C95ACD13C3C906297BB4 |
|
CONTENT
ssdeep
|
768:aN+EsZx8/G8s048DawxM5BWwEqM5BnwzqN2/y9dGDUDF1E56ITmH+LXPnTyPqDvQ:aN+EsZ/8sv8DawxM5BWwzM5BnweN2/yb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eab4954ae41bf324 |
|
VISUAL
aHash
|
ffffe3e1c09818ff |
|
VISUAL
dHash
|
e8974f0703233104 |
|
VISUAL
wHash
|
7fffc0c0801818ff |
|
VISUAL
colorHash
|
076000c0000 |
|
VISUAL
cropResistant
|
e8974f0703233104,071f072727272727 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.