Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17E54FB719218B93F1197C7D4EB316A29A3AED218F9664251CBFEC7791AD3CA0FD0B014 |
|
CONTENT
ssdeep
|
3072:PIBaHNo79DePHiYdAN+RcUK3K79Vi1Qeu3vTXc:PIBe44579Vi1Qegvw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8486dd7359b389a6 |
|
VISUAL
aHash
|
ffffffff00000000 |
|
VISUAL
dHash
|
98e7e6d800800c30 |
|
VISUAL
wHash
|
ffffffff00000000 |
|
VISUAL
colorHash
|
32000018180 |
|
VISUAL
cropResistant
|
00c0c1a2a2a1c000,8890e7e700e4c080,0004c484058280a0,7fffffffffffff7f,7fffffffffffff7f,0000000000085432 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28643 techniques to evade detection by security scanners and make reverse engineering more difficult.