Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T145428533E600DC2A4D9B5188F5C49688515ED34AFB3208C6A160A1FF7BC9DF129A93AD |
|
CONTENT
ssdeep
|
192:Kmq0RYc8cdchpTnqtIRxp0DE7G1McnthWeNWbHOdxfMmUU8VCohcN:KmEc8cdch5nqkiMGsOdxfMmUFCohI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e275187c662add2a |
|
VISUAL
aHash
|
00fffff7e7ff002d |
|
VISUAL
dHash
|
a2ce004c4d004949 |
|
VISUAL
wHash
|
00e7efe3e7ff0000 |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
0c0c0c4d0d004949,2020a0a04010a0ca,0000243232301400,0121516c6c4c1200 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.