Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12BE497E44219123EE85B83C95F25372923FB90FAE6639184AAFD037572CBCC5F5528C9 |
|
CONTENT
ssdeep
|
1536:gnNnKnknQnZnoninynNnEnPnHnGnSvnLmnZnBn1nwn9nYnVnDntnSXnVnonYn0nL:nxUctif1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f9f107c7066e4634 |
|
VISUAL
aHash
|
e7cbc3c9c9c9c300 |
|
VISUAL
dHash
|
ce9a9333333b2b0a |
|
VISUAL
wHash
|
e3cbcbcbc9c9c300 |
|
VISUAL
colorHash
|
06e10000000 |
|
VISUAL
cropResistant
|
cc70522327e5e5a3,e030b01818583830,f0e0c1c306d0e47c,b8f8dcf1e2f23c70,ce9a9333333b2b0a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.