Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T127735071B2435A2FA25BC0C1F6155B9EB38A570EC3130E85B7F583766FC2C2AED22615 |
|
CONTENT
ssdeep
|
1536:EuBwm0mDsdhBSZjl4h01ZjGLhBSZjl4h01ZjGICLxQP/0LVRD15FsjF:Wm0MjbjfjbjWNLVvsB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e7ec9a98ddc29a80 |
|
VISUAL
aHash
|
fbe0f0f07b3f2723 |
|
VISUAL
dHash
|
23626746e2e9ef6e |
|
VISUAL
wHash
|
fbe0e0e0333f2703 |
|
VISUAL
colorHash
|
06007000040 |
|
VISUAL
cropResistant
|
23626746e2e9ef6e,79f8dcfebe9ef2be,540c2e361cb42c0e,8cac8c6c48d8d9d3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.