Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BB9273A426204A7F948783B0F7653F39F18DD38AEDABC919E2FE81A507C3D44DD90264 |
|
CONTENT
ssdeep
|
192:DTWDWj0KxQ00CVrrStKkDK7YD0I6FRCibbgrud7pAIIxQ/fn:DTJT1VDxc67bgrApADxun |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96916988c4d6ddd5 |
|
VISUAL
aHash
|
ff3f1e3f3f0d0000 |
|
VISUAL
dHash
|
fedd7c6c6d7969e4 |
|
VISUAL
wHash
|
ff3f2e3f1f0d0000 |
|
VISUAL
colorHash
|
0b002008000 |
|
VISUAL
cropResistant
|
fcff5c7ced6d7969,2c7c3e76e6d40890,9bf2e280c0c0e0e0,ffdd7c6d7d7969e6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.