Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B6B2943212442D6E361386F9FBD0BB6994EFC36BD68B8D1CF27E81A15792C94D917380 |
|
CONTENT
ssdeep
|
384:Io/RTPxeW8unKiWbqahIaUBIhQLVQVuPWHucrubx9eqk3jBgf:IoBPxeWhKiWbphZUBIhGouPgu4ubx9Xj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d92929243e396 |
|
VISUAL
aHash
|
fbd1d1f1ffff00ff |
|
VISUAL
dHash
|
6333336330d02035 |
|
VISUAL
wHash
|
f90181b19fff00d5 |
|
VISUAL
colorHash
|
07000001081 |
|
VISUAL
cropResistant
|
6b333323533238c0,20802031156a1517,e5e19696e08b80c1,000004d1f1d00400 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.