Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FC244350F2E29C32305F81F2A4A467091092FBBBC7411FC767B157B5ABF58B9384E299 |
|
CONTENT
ssdeep
|
3072:IRvSI4y/Apfb6mAuM0evkS+GY07MPBd0rGRlOz6q0kvNq+ZcOWzn9x87/jSeOC3Q:I+wdnoklvMK+n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
877f78000f7f0f60 |
|
VISUAL
aHash
|
007f3f3f3f3fffff |
|
VISUAL
dHash
|
00a04050d0d0a0e0 |
|
VISUAL
wHash
|
00003f3f3f3f073e |
|
VISUAL
colorHash
|
06007008000 |
|
VISUAL
cropResistant
|
8000c082a2800080,a04050d0d0e8a0e0,4145808280c02120,2424254dcdcd5d5d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 53 techniques to evade detection by security scanners and make reverse engineering more difficult.