Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C2436374B052A77B10D3C3F277796B6BA2E1C249C7271A4793FA839C0BD2C51ECA2194 |
|
CONTENT
ssdeep
|
1536:V8LutG+Igzh7I9IMCrtZT0B6wqRKz3QsVs:kO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c3e9764d933718c |
|
VISUAL
aHash
|
003c3c1818003c7e |
|
VISUAL
dHash
|
b4e0e0b2b286f0f0 |
|
VISUAL
wHash
|
1a3e3c3c38407e7e |
|
VISUAL
colorHash
|
30400048001 |
|
VISUAL
cropResistant
|
66a6ccca7eb6d6c6,b4e0e0b2b286f0f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.