Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B292B97380C9977B2273D7D4D610A61CF38B6655CD6E2924C6D5C38F4AC1FB0CCA52A9 |
|
CONTENT
ssdeep
|
192:/NymJEEFqWQNiQkW5u5lCJGMR/EbBW6/JJ1JTgYYXbibKCLe6ti2ggsRZt5Tttki:9E0Ts45M4MJEcgXJYriBLht6Rpbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e699079e6c66592 |
|
VISUAL
aHash
|
40183c3400007e3e |
|
VISUAL
dHash
|
843369692933fcec |
|
VISUAL
wHash
|
46183c3c3c187e7f |
|
VISUAL
colorHash
|
080000001c0 |
|
VISUAL
cropResistant
|
08a9ca48d8d35179,843369692933fcec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.