Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14913A2719100AA3B41D3E3D477711B5BB2D1C189CEAB061B52F9C3ADAFE7C62DD58A04 |
|
CONTENT
ssdeep
|
768:uNc7NEjk44/1cOqtCAeeeReeeLeee/eeefeee1eeeR1/GLYygpqp/QVOR78oU3r3:Mc7NEjk44/1CtreeeReeeLeee/eeefeA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8552e97aec961593 |
|
VISUAL
aHash
|
000026040000ffff |
|
VISUAL
dHash
|
b2c1ccece3d46a62 |
|
VISUAL
wHash
|
c0707e760000ffff |
|
VISUAL
colorHash
|
3a207000000 |
|
VISUAL
cropResistant
|
b8fcf47819999894,e0c0e57272627676,b2b3ccccecead5e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.