Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17CC13E60D069CC6F014B81D5B2319F5E77A1D280CB334B0463F8A7BE6AEACB6FD56244 |
|
CONTENT
ssdeep
|
96:Tgg4N+9UQvGPjhnj27jTeljfxjGijw301C5QkyUM5:3O+aQvMjNjujqljZjpjwEw/yUM5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
930eef342de1949a |
|
VISUAL
aHash
|
041c3c4c0eceeced |
|
VISUAL
dHash
|
547078d838989a4a |
|
VISUAL
wHash
|
0c1c3c4e0ececeee |
|
VISUAL
colorHash
|
02002000180 |
|
VISUAL
cropResistant
|
d2c0c6d4c6c6d3e3,f0707078f6fee0e2,81838481c08cf8ff,547078d838989a4a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.