Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7326233E600CC298DAB558CF6C09A89401DD346FB3148CAB1A491FF7BD4DF069A939D |
|
CONTENT
ssdeep
|
192:Kl3JZdZ9gwaZZ4NOGx7K1McnthWeNWbojCzcrfMmUU8VCot2:2Z9gwaZ2NFKt+zkfMmUFCot2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb67344b9c19b43c |
|
VISUAL
aHash
|
00203c3c3c3c38ff |
|
VISUAL
dHash
|
69696979696969b2 |
|
VISUAL
wHash
|
003c3c3c3c3c3cff |
|
VISUAL
colorHash
|
02000000038 |
|
VISUAL
cropResistant
|
1505313035803b23,0000010000000000,6969697969696961,0694954a8c8ed0c8,0110083034081001 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.