Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15332507115023BBB635B8999B6225BC970DAF70DD923C508A2FCA2C11BD6CD1DE42B53 |
|
CONTENT
ssdeep
|
192:/6SKOVANkikoFoDixu46ySJCtaIBLEA8a:/6iBikrDKuLj69BSa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aff00ff0092cc91f |
|
VISUAL
aHash
|
ffe7f7e7e6ff1719 |
|
VISUAL
dHash
|
330d04040d0c6f73 |
|
VISUAL
wHash
|
81e7f7c3c0ff1300 |
|
VISUAL
colorHash
|
07041240001 |
|
VISUAL
cropResistant
|
330d04040d0c6f73 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.