Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9428433B500DC2A8D9B65CCF6C496885159D345FB324887B2A091BF7BC4DF529E83AD |
|
CONTENT
ssdeep
|
192:3dO07xbMcnthWeNWbXHbVKiLBfwRBgazmlFFJz/fMmUU8VCoiVi:tKHbBfwRBgazmDfMmUFCoiVi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb4bb65ad9b400cb |
|
VISUAL
aHash
|
f8f8f8f8f800ffff |
|
VISUAL
dHash
|
d151d39201111600 |
|
VISUAL
wHash
|
781838f83800fffe |
|
VISUAL
colorHash
|
06000200038 |
|
VISUAL
cropResistant
|
11d161d3d252c111,80808080b5bfff7f,0000000000000000,de939769e9f16161,0000243212100810 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.