Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F3F101E1C554EE3B475286C5EBB56F4B7691C389CB47084093F883BBABCAC60CB2159D |
|
CONTENT
ssdeep
|
192:QWBfzeTkGTqIMl9d0QE6IMVfLyIM8skIMh1Pd:QqOlTHMl9GzMVfL/M5RMh1Pd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c93936c93646c |
|
VISUAL
aHash
|
fff3f1f1f1f3ffff |
|
VISUAL
dHash
|
0026272726061006 |
|
VISUAL
wHash
|
7f1181819181cfcf |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
0026272726061006,f8f2f2c0ecfefefe |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.