Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17693867729492E7731C362D0F31DA68AF743C20DC3B2C556B7B9438B7582DE69A290E4 |
|
CONTENT
ssdeep
|
768:RpjHL5pXnfFmHvmZbbTJA2F1/PDllCWAjHL5pXnfFmHvmZbbTJA2F1/PDllCWYRa:r0yRNS0sVl840HBccectf0WxmLj8I/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2506d369696b666 |
|
VISUAL
aHash
|
00003c7e7effd1ff |
|
VISUAL
dHash
|
8c93d0d0cccc33c7 |
|
VISUAL
wHash
|
00003c7e7eff91e3 |
|
VISUAL
colorHash
|
0e0060000c0 |
|
VISUAL
cropResistant
|
d0c8d4cccc33279c,8c93d3d3ccccd4dc,4551253131394551,a059595aa7d3dbf2,00454d71714d4580 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.