Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15DC2B9F1A055AC31A2A3CDCF6B606B596593E247DA130E86C5E5C36827C6ED7EF23108 |
|
CONTENT
ssdeep
|
384:vQQj+Y4902042+78/3JiuC6rNbPuDiev+qEuMnbV1tvhgqa1KF:vQQR490B4D8/3R3xKDNUbTtvhgq4KF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce3364313333317d |
|
VISUAL
aHash
|
00383c3c3c3c3838 |
|
VISUAL
dHash
|
6961616961616161 |
|
VISUAL
wHash
|
3c3c3c3c3c3c3c3c |
|
VISUAL
colorHash
|
39032000000 |
|
VISUAL
cropResistant
|
e21842a238fa6272,89b9b9d827251d33,6961616961616161 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.