Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1668385256815DD3F15AF2BC862BA1A1E22FAF344D96241C4E599C3F457E7CACEB33420 |
|
CONTENT
ssdeep
|
768:UJDr6O5n2ol/VsqLfzZHO9UmUdbz6XuYfrAjg3iTmY/R75RCUG:UV52oxNVddbKuYUjg3iTmY/R75Rm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f7332d0e544c2d1b |
|
VISUAL
aHash
|
00efeffcfcffffff |
|
VISUAL
dHash
|
440c0b0c0c2f2b4e |
|
VISUAL
wHash
|
00a7efe0e4e787e0 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
2d4c0b0c4c2f1a4e,004024d4d4d42200 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.