Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14181C734A423B8336467C2E195E7AF0A2293CA0ADBD3335347F4179E56D6D04ED861F8 |
|
CONTENT
ssdeep
|
48:VAVVd6jPJYoD/k6jPBrRV9FP1A2AFP5fJtWtFPodZFtofty1H748rxzkCzqI7vFU:q09TBn9YLfqtcTofkB1vzqwu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cbf09728e15e88f2 |
|
VISUAL
aHash
|
ff7f7ef878383838 |
|
VISUAL
dHash
|
e0c6e1e3a3e361e1 |
|
VISUAL
wHash
|
7f3f787070383838 |
|
VISUAL
colorHash
|
07200618000 |
|
VISUAL
cropResistant
|
e0c6e1e3a3e361e1,176361e1e5636364,2d2c2c2d0009050b,0919512519030b0b,6060606060203030 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 83 techniques to evade detection by security scanners and make reverse engineering more difficult.