Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11C5363716941DD3B41CB9AC85932462662F98345D6630289FBF8CBF94BEFC6DCA33910 |
|
CONTENT
ssdeep
|
768:wcmsIx/ju9ybu4ZELk+CucovoAs6s6s6s66TWWgQoUf747cH+K0P1:wJsIxq9Il+CvovvXXXX87ud1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9dfaaa1c1a4d88a |
|
VISUAL
aHash
|
ff009cfef88083cd |
|
VISUAL
dHash
|
386838689a1aaf99 |
|
VISUAL
wHash
|
ff081cfed88803cd |
|
VISUAL
colorHash
|
06006000000 |
|
VISUAL
cropResistant
|
00000080a080b038,98189248589ac868,8aa2826c2c82a2a0,287838ea9a1aaf99 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.