Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15FB29630A112BA3B9067B3D0BB65CB1733C052CAE74347655BF883A9CADEDB0ED15685 |
|
CONTENT
ssdeep
|
384:VB8NQqAO5fc5GE71+/q/L/Pi/c/o0AXJA67AxqAU/HW4p:VB8N5AO58GEtAXJA67AxqAU/v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c1f4361585f1f1c |
|
VISUAL
aHash
|
003f1f9fdfe7ffff |
|
VISUAL
dHash
|
f07c783eb60e4e90 |
|
VISUAL
wHash
|
00071f8f83e30f7f |
|
VISUAL
colorHash
|
07000000380 |
|
VISUAL
cropResistant
|
00a280e2e280a200,9e743836b64e2ed8,07b0f170b00ed0d2,3355030341010909 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 66 techniques to evade detection by security scanners and make reverse engineering more difficult.