Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T157628562D6016C2F1273C4D5F7DEBF9A6286514CCB8247A262F843AC0BCDD11F9E25AD |
|
CONTENT
ssdeep
|
192:JjlZJD+9aR1hOmTPs3s/CaOaTCuUV3SOqOXoUibT/ZHgdRfbfvjDBbjnL:JjRuGOmTk3sKaOaQVZqHbbRgDfvjDh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a9f686d983e608b3 |
|
VISUAL
aHash
|
ffc381818199c301 |
|
VISUAL
dHash
|
082f3333333337cd |
|
VISUAL
wHash
|
ffe781818199c301 |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
082f23333333330f,3efcecccaad8d061,9e6169b239717133,19c04d61d1d50100 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.