Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11B929571A0502A3F2167C3CDB352B72EA1D39249E785180692FC4B5ECBE6F90D91786A |
|
CONTENT
ssdeep
|
384:Vpy5NikR2V24leBDKIKzyE25EJwGfBNd6/2z+GjxmeO25XIYsOy2+y9BH4cCUIe:Vpy5NikR25yEpJw0BNd6/uxmeO2J7sOF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8363f8369169c7c6 |
|
VISUAL
aHash
|
000020000400ffff |
|
VISUAL
dHash
|
9dc9c3c34c0ce300 |
|
VISUAL
wHash
|
000d71702e06ffff |
|
VISUAL
colorHash
|
31408000400 |
|
VISUAL
cropResistant
|
0080800270908000,9c19c3c1c24c6ce2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.