Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115F3FEF3E2B84936126B43E5159A3DC9FECF8547CAD586B0B374A34E97D0A842B0395C |
|
CONTENT
ssdeep
|
1536:W0HiHDcPyONFaQkeH0pLHmbtW/Vyuj6d+YFfy6B88M:mH/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e633a16d9a57311c |
|
VISUAL
aHash
|
f7f7a4848080f2ff |
|
VISUAL
dHash
|
6ea6446525266664 |
|
VISUAL
wHash
|
f3f3a2908080f2ff |
|
VISUAL
colorHash
|
06e00010000 |
|
VISUAL
cropResistant
|
6e24456d2526666d,c3c60c1890c4c4f9,100030b2b2300020,fffffffffde5e58e,e3a3c30d0d01f382,2074383d959919e1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.