Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T102A2465121085A56C2F34DD894103B817286DB4FC87187B0C2BC4E7B1BE6AA5B7E9F7E |
|
CONTENT
ssdeep
|
384:2Tzh0GyP9baRTS6agJY863l+3Hr7Wo6wbGRavx:ISoY89xGRavx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
daad4252b952e565 |
|
VISUAL
aHash
|
fff3f38f8ffcfcfc |
|
VISUAL
dHash
|
9c27073818000800 |
|
VISUAL
wHash
|
0091818f8ff0fcfc |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
9c27073818000800,0008343232300810,d494d09096d0c982 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.