Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BD451BF013281A3BA08BC39DDB79BDE622AD99D6EA83454493AE4BEC57C7CC4DD055C0 |
|
CONTENT
ssdeep
|
12288:F4d7LZLCinAtOSb/UrtCzqqXSQaDqYzMaC5:abjSZ2RD5zMaC5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f70037e671d7609 |
|
VISUAL
aHash
|
00ffff9f939f3b3b |
|
VISUAL
dHash
|
7531b436273572d6 |
|
VISUAL
wHash
|
00df1f93119f1b17 |
|
VISUAL
colorHash
|
06042000040 |
|
VISUAL
cropResistant
|
7531b436273572d6,0100053131090101,01010f41a1894115 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.