Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1474395718018AD3703A392C6B7B2979FB2D18209CE431A16D7F4C79C5BF7DA0DE1991A |
|
CONTENT
ssdeep
|
768:UelkIc+IGO+XNDh8ao54Nosl5jO222i2N+2PX77mlgq9W7g1Y8RMTElk:U62sl5jO222iNY8RMTElk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93936c6c6669b398 |
|
VISUAL
aHash
|
203c3e2c003c1818 |
|
VISUAL
dHash
|
c4d8d8d86071b232 |
|
VISUAL
wHash
|
307e7e6e383c3c18 |
|
VISUAL
colorHash
|
30200030000 |
|
VISUAL
cropResistant
|
c0f1b1e8f03170d2,0458069e96064814,c4d8d8d86071b232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.