Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1166121B0501669BB029792D877B6970B33C043D8DFA31A112AFDA3BD1BDAE54FD021D1 |
|
CONTENT
ssdeep
|
48:TGupx7VJZSUWPrgEDAdLAo3+jcoiQ5UgqCadufZl68f8W5AI:TGuzVJZSRrLAdLDu35Ba0fZl68U4AI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3764c4c5d196666 |
|
VISUAL
aHash
|
00e7e7efe7ffffff |
|
VISUAL
dHash
|
b20c4d4c4c20000c |
|
VISUAL
wHash
|
00e7e7efe7e78000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
084d4d4d4c30000c,0000343430342400 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.