Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T121D397FBC0A53D352B9A82E752013ED97546A10B9A428CA6E3DB538CB7C1FF6F535048 |
|
CONTENT
ssdeep
|
1536:n3YgcT2441Ll8Eh+jw+xlr3ddJGDs5hsgmfDhf36ZJOcGO+GEvA0NAFNnOxSsMHU:n63dppTF0T/p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ffa2c17dbe021c2 |
|
VISUAL
aHash
|
ffbfffff3f030301 |
|
VISUAL
dHash
|
362ec8b77b76e7eb |
|
VISUAL
wHash
|
ff9fff1f07030000 |
|
VISUAL
colorHash
|
07000008180 |
|
VISUAL
cropResistant
|
362ec8b77b76e7eb,d3b498ca261a34a4,0f1374696d696969 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.