Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T180D2D631B080BA3B41C787C8F3F2E72E65E78289D916060942FE976D5BE7D40ED7641A |
|
CONTENT
ssdeep
|
768:N1wy5N2eUdSNqgKlZtnSECOsOiWM1QR+OjAF7sBLy2+y9l0K4/LIe:cYhosd8pAF7sBLy2+UuK4/LIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9369ec128d6c92ed |
|
VISUAL
aHash
|
000000000004ffff |
|
VISUAL
dHash
|
1d194b43c95ce200 |
|
VISUAL
wHash
|
00ede1002c0effff |
|
VISUAL
colorHash
|
39400038000 |
|
VISUAL
cropResistant
|
feffff9f9ffffefe,00c0c00058988000,1419494b43c9dce2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.