Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D728670C151A427027283D4A772071E97D2A349CF634B06A3F88B4E5BFEE86EC57769 |
|
CONTENT
ssdeep
|
192:n2J0cPpRx9Nx9Px974eaC7qJ4dYG0wnNxrSkGgES5:n29Ppb9f9p9ZYEH0wnekGha |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc7c8b0135f46ac4 |
|
VISUAL
aHash
|
000080800200ffff |
|
VISUAL
dHash
|
1b65243666e1542b |
|
VISUAL
wHash
|
00b8f0c2b300ffff |
|
VISUAL
colorHash
|
02000000006 |
|
VISUAL
cropResistant
|
1849c9342199b136,ae8eaea2baae8ea2,9749858189c1c5c7,000045314d4dd02b,014b65343626e629 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.