Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11051DAA02160AC3B4223C7D576E66B6B32D5C356CF5726008BF8C76E2EFADC1DE15145 |
|
CONTENT
ssdeep
|
48:TRB2lTOVWJlw3+OIIpZ3OKhjqhh7w2rbOt945:TRiJiuOIIqajuqtk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c9933a6e6b3998c |
|
VISUAL
aHash
|
ff003c18381c0000 |
|
VISUAL
dHash
|
0c3031713131300d |
|
VISUAL
wHash
|
ff003c3c3c3c00ff |
|
VISUAL
colorHash
|
310000001c0 |
|
VISUAL
cropResistant
|
0020402020400000,c07834b189a08080,0000006b2b230000,0030713131313000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.