Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1983362E1488D713F41A77981AAA9F769B3D24248CF161A40A3FCA35DDBCBF41DDB110A |
|
CONTENT
ssdeep
|
384:EcdjId+HqroUa87TJFWkCIBwNLTyecLcnf7lJCersY0zOrGUY08v2Dxt3a0r36B+:EcdjI0Uf7b87lJHsY0XDGS/JGT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc1c4f674c68634b |
|
VISUAL
aHash
|
008fcfdfffffffff |
|
VISUAL
dHash
|
2a3838b0300c0f2b |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
0000203232324060,283830b04d0e0f3b,6000c1d4d4010000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.