Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110240FD982518123197361C303BE972272F047CAF5979C75D2FC47E916CDE92BA8B82B |
|
CONTENT
ssdeep
|
1536:kuppuY0xbVHzHohojtDowUlewouZNHJFJQW7rK2f4Z2wqTD5bMqV/5f5X5QvC5UE:kupst85o2qxO3IWiy1R/x75 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
80da78de7cf8d860 |
|
VISUAL
aHash
|
7f7f677f777f4343 |
|
VISUAL
dHash
|
c0ccd6ccccc89696 |
|
VISUAL
wHash
|
7f7e427e667e0200 |
|
VISUAL
colorHash
|
0e000000188 |
|
VISUAL
cropResistant
|
c0ccd6ccccc89696,0505050505050505,0d3337393185671f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1034 techniques to evade detection by security scanners and make reverse engineering more difficult.