Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T102535130A511E92B41DB99C46272176AB2E58309C6130789FAF8C7F85BEFC5DDE33A05 |
|
CONTENT
ssdeep
|
1536:n2B79jIv6ioH9Tn+3cXcVwCeyeVeseqcHaS3UcqsIxq9LUH79F:n2B7+KoaS31qVH7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
87cbb8edaa545d04 |
|
VISUAL
aHash
|
ff7f202133000206 |
|
VISUAL
dHash
|
a3cbd4c96752f63c |
|
VISUAL
wHash
|
ff7f3e2d33020206 |
|
VISUAL
colorHash
|
16403000040 |
|
VISUAL
cropResistant
|
06030b03038b02a8,0000000000000101,c9c459e763d2b43c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2957 techniques to evade detection by security scanners and make reverse engineering more difficult.