Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T196C2097183D65A37054383C4BBF2DB1BB3C58199EE27874196F48BB973CAC88DC16608 |
|
CONTENT
ssdeep
|
384:2II7k25pDeyJD3YNb85DwN1CBAjyXkyT5dOtPrQt8mXtV9:2II7pbTSwOIBGybT6tif |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
986c9666b63a9533 |
|
VISUAL
aHash
|
0418181824183c7e |
|
VISUAL
dHash
|
6c70b2f1ccf0f0dc |
|
VISUAL
wHash
|
1e3c18193c3c3e7e |
|
VISUAL
colorHash
|
30000010c00 |
|
VISUAL
cropResistant
|
e4e6f0484c6c383e,0f8c7147676517aa,6263696b636b6bb4,6c70b2f1ccf0f0dc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.