Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T138B2FA60321444DD1B47439BF5A17A6DE38BFB8AED00DD1890AD47B981D9FB0D8636F1 |
|
CONTENT
ssdeep
|
384:KgS2MuCjSSJJo9d09dh9dTp/2deYOWdeYtle+9HdeY/UdrdTdJOQ97djKdlsde3B:9PMueSSJJo9d09dh9dt/2deYTdeYzde6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce8e8e2a2333333b |
|
VISUAL
aHash
|
913c3c0000000000 |
|
VISUAL
dHash
|
3170690400000000 |
|
VISUAL
wHash
|
ffffcfcf00000000 |
|
VISUAL
colorHash
|
38000000000 |
|
VISUAL
cropResistant
|
82a28e868696a2a2,3170690400000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.