Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CCB25211A09604A30073E6C0E0E77FD965F7FB26D00F422965AC9975AFDFE2D72281A7 |
|
CONTENT
ssdeep
|
384:Bi6/NGOVHh5TlJqsa9YyGKKepPMUI1LgwB/NGOVHh5TlJqsa9YyGKKepPMUI1LgW:BP/NGOVHh5TlJqsa9YyGKKepPMUI1Lg6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb84c13fd2790e62 |
|
VISUAL
aHash
|
fffffbc9810188ff |
|
VISUAL
dHash
|
c8c6333b2d731b0b |
|
VISUAL
wHash
|
76ffdbc9810088e3 |
|
VISUAL
colorHash
|
06203010000 |
|
VISUAL
cropResistant
|
c8c6333b2d731b0b,0101012383095161,0617d3d315c94d79 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.