Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D8C2B434E0846A3742C792D8F7B1372BB375C288D6061214CAFEC3694FD7C49DA976A9 |
|
CONTENT
ssdeep
|
768:A1SMf3Y7kVkcQW1Mfkq3KS7s7y2+y9Gt491Ie:Of2Wusq37s7y2+UGt491Ie |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c703b53ab02cdcbc |
|
VISUAL
aHash
|
002000000000ffff |
|
VISUAL
dHash
|
4cc8e4c8c8e0e700 |
|
VISUAL
wHash
|
00343070ec70ffff |
|
VISUAL
colorHash
|
31000c00000 |
|
VISUAL
cropResistant
|
408080006c848000,2cc8e4c0c8c8e0e2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.