Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D0D21F319411AA3B0193E3D5AB75AB9FA3C68209DF730B4663F4831E5FEBC81CD26255 |
|
CONTENT
ssdeep
|
768:PVugdnVlrS9TUlvZ/1Dn046Wvv3UesnzE0uLePfTR4zTy1/F:PlrS9TUv1Dpg4zTy1/F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ede912d21af2164e |
|
VISUAL
aHash
|
f9fbfbdbdbfbf100 |
|
VISUAL
dHash
|
23125232326363b6 |
|
VISUAL
wHash
|
00fbf3cb9bf9b000 |
|
VISUAL
colorHash
|
064400000c0 |
|
VISUAL
cropResistant
|
23125232326363b6,00000020d0d08020,0051d9d1d1f5f5a5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 52 techniques to evade detection by security scanners and make reverse engineering more difficult.