Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA7230E1D090DD3A575286D8B7F57F1B33A1C385CF06098423F452BA9BDEDA0CB2259A |
|
CONTENT
ssdeep
|
192:Qh3c3O32OF6kzYhhN3Zc/A8iOdMKp/WF6ZOdlNvNph3izO/TvDlU8F:QhM+TFGNpc41OqKp66ZOTtrJTvDa8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc2c8fd380dc82f3 |
|
VISUAL
aHash
|
9b8183c3c7efffff |
|
VISUAL
dHash
|
333327368ec816ce |
|
VISUAL
wHash
|
91818183c3efe767 |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
333327368ec816ce,66c682c0fcbc9891,03ae4c4c2d1d8d44,400021310d337393,0f396963b95b630f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.