Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T167A30F238269762B4437C3C1307A5B3BD1A6998FFEE709410EDCC7F62AFAC90741A559 |
|
CONTENT
ssdeep
|
1536:CXtpR4nXBKpSpFl26vdC8cxLQUK/LDTHqBz:CjUMCC8cxLQUK/LDTHqBz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f2ec6d92926d6d10 |
|
VISUAL
aHash
|
f0f0f0ee6e040000 |
|
VISUAL
dHash
|
0001020ccc4d2928 |
|
VISUAL
wHash
|
f8f8f0fefe8c0004 |
|
VISUAL
colorHash
|
100000001c0 |
|
VISUAL
cropResistant
|
202210c080000101,00008060608000a4,c900806068e08080,8000a040c0808080,80008080a0808080,0001020ccc4d2928 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.