Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10B0372305451AA37018393C0FB7157AF63D1D2A1CF130A4AA3F89B2F9FDAC91CE195A9 |
|
CONTENT
ssdeep
|
768:nojIvhJGS0ZfIq6uj2A+66sbrBl4QHfNxzoUFUGdLF:nojIvhg7ZfJj7+66sbrBl4QHDZUGdLF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92c52d91ee15ba65 |
|
VISUAL
aHash
|
ff7e7c7c7c0c0481 |
|
VISUAL
dHash
|
b4c0e8c8c8f9381d |
|
VISUAL
wHash
|
ff7c7c7c7c0c0081 |
|
VISUAL
colorHash
|
3800b000200 |
|
VISUAL
cropResistant
|
04708d9e9e1c6004,b4c0e8c8c8f9381d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1504 techniques to evade detection by security scanners and make reverse engineering more difficult.