Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E6828AA361C0E92F4FD137AD79207F6C07F311A0A3810D4869AA5E5FDDB8BA455026EF |
|
CONTENT
ssdeep
|
96:sKr1WHet5T52bmsq4Md/pQAT/envl15YRtnxQf7ZOJxunNC2RYENe80YIBZ50p8y:1M+zEvMdRj/LJbGMGkZmDEumSnqvW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bfaa22aa22aa2a6f |
|
VISUAL
aHash
|
01bf9b9b9b9b9966 |
|
VISUAL
dHash
|
03525373737373cc |
|
VISUAL
wHash
|
018b9b9b999b9966 |
|
VISUAL
colorHash
|
071c0000000 |
|
VISUAL
cropResistant
|
b08c8e8e868e8cb2,03525373737373cc |
Victim enters credentials into 10 fake forms. Form data is captured via JavaScript or backend submission and transmitted to attacker's server for account compromise.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.