Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17E03773463882A7F615787E5F661BB7CA0B9C34AC73BD44DF2B8426257CAC4899132E4 |
|
CONTENT
ssdeep
|
768:58+mErs22PkATJr9HJVQtSgWjIg5r09qlRy+l:+TV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
af94c0ca592d367a |
|
VISUAL
aHash
|
ffff838389819181 |
|
VISUAL
dHash
|
712d0f5353735353 |
|
VISUAL
wHash
|
ffff878381819181 |
|
VISUAL
colorHash
|
0e400030000 |
|
VISUAL
cropResistant
|
712d0f5353735353,f0d8989830906061,16261c78e0c1b0e0,2e5353d0d2b3d352 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.