Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A2D221718441A63B029BE1C0A6756B4F77C28788CF631A0667F8DB5E6FCBE54CC653A0 |
|
CONTENT
ssdeep
|
384:UsoXHrSymseb9Gs90s90s90t+HlJTO+DxDKDxDKD3DsD3DoDRDKDxDKDpe7htK3V:U1oAs6s6s6UFwrUf7d |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94b64b4bb4b44b4b |
|
VISUAL
aHash
|
0126660606600000 |
|
VISUAL
dHash
|
7354ccdc94d0e4c4 |
|
VISUAL
wHash
|
83ef66c706640000 |
|
VISUAL
colorHash
|
18000040038 |
|
VISUAL
cropResistant
|
d9ccaab297d4ddf9,7354ccdc94d0e4c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 71 techniques to evade detection by security scanners and make reverse engineering more difficult.