Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1295381DC93B5622B53BD30CEF8030A5AF6CA457EC40F2DA3B55DE59E2DC1A1B96E1018 |
|
CONTENT
ssdeep
|
1536:/QtG1vmWMh17OwmNx615m9GV1dmJI312mvkb17mUV:4t+NMr6xKmGXsIlLkRV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e464cccb99999acc |
|
VISUAL
aHash
|
d1321208f1ffffdf |
|
VISUAL
dHash
|
2564249a610b0e32 |
|
VISUAL
wHash
|
d110300030ffffdf |
|
VISUAL
colorHash
|
074000080c0 |
|
VISUAL
cropResistant
|
2564249a610b0e32,ab76362e6e6b7a66 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.