Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD621C3474503A3745C392E667227B0BB3E2C396CA2757492BFAC3A85FD7C6ADC56210 |
|
CONTENT
ssdeep
|
192:H7DFw0Moqerf5f8XVmi5xv9i281DIlNzu9RxQgSXsXma/ImFKKf1vK9TKYp/Cft:H31LbKxv02As/MHQgZDwwKaKxKYpaft |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
df96a4b58a8ea0b1 |
|
VISUAL
aHash
|
ff00001800000000 |
|
VISUAL
dHash
|
6a00006130000001 |
|
VISUAL
wHash
|
fff0e0fcf8c0c0c0 |
|
VISUAL
colorHash
|
01000180003 |
|
VISUAL
cropResistant
|
0808826c62820808,256542d39267e2e2,0004607110000001 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 43 techniques to evade detection by security scanners and make reverse engineering more difficult.