Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E642C6BDC280F53B5306C1C1AEAD77ACA7874E4FE6D71B1148BDC42DA491BD9C909178 |
|
CONTENT
ssdeep
|
192:2d+76SYiB7Ula5cVYSJQT44lMthsOE/ZEr0lLtfwIsQKeZKp8n2C:tYiBf5LSO44mPsOEMMHKVpO/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec1b46161616dbcd |
|
VISUAL
aHash
|
0000fbfffffff7f7 |
|
VISUAL
dHash
|
6912120c12362727 |
|
VISUAL
wHash
|
0000c3c7fbc7d3e7 |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
8000c0d0d05000a2,12120c261a272707,61696961699bf906,00219a86de0b8441 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.