Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB227223A600DD2A4D9B86D8F1C49589416EC345FB3048C671B090FF7BC4DF0A5A979E |
|
CONTENT
ssdeep
|
192:UcHDNdLh/4K1FyqdDxU0fxiMcnthWeNWb5HfMmUU8VCo4qaE:rLhT4UfMmUFCo4O |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8101ab2957fb4ddc |
|
VISUAL
aHash
|
007e7e7e7e7effff |
|
VISUAL
dHash
|
dbccccccdcd400c0 |
|
VISUAL
wHash
|
00246e243c34ffff |
|
VISUAL
colorHash
|
06243008000 |
|
VISUAL
cropResistant
|
dbccccccdcd400c0,2fab2fbf33abb323,73536333e3d3431d,a49218065751d6d6,6e381adbea200000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.