Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8E2C77A134C2B3D91178BA8FBB5F338925DC3ADE21B9959E7AD02714283D85D8332D4 |
|
CONTENT
ssdeep
|
768:mk07QBsTvIj3VgbCOJ+9xQxkj7E/0kaNcFK:/lg2OJ+9G4pkgc0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83ac7ca4d8ac78a |
|
VISUAL
aHash
|
fd8787878ffffffe |
|
VISUAL
dHash
|
2b3e3e3e3ec01d2a |
|
VISUAL
wHash
|
9983838387ff8f82 |
|
VISUAL
colorHash
|
07030000400 |
|
VISUAL
cropResistant
|
2b3e3e3e3ec01d2a,f7d39393998f8737 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.