Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17DF1B5E2931854FF2593DAF8698EB711E065C187C5F72C46E1EC82F693C6CA4DB2B240 |
|
CONTENT
ssdeep
|
192:UYjfYPMY/sWW5LuDZRH+wuKZsgyiiiigIBqA3fhwK:0rW5LuDZRH+wuKZhW3wK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dde662996699238c |
|
VISUAL
aHash
|
f8f8d8d818181800 |
|
VISUAL
dHash
|
1030103032323204 |
|
VISUAL
wHash
|
fffcf8f8d8181800 |
|
VISUAL
colorHash
|
00000000007 |
|
VISUAL
cropResistant
|
b0fac69696b6a4d5,a280a2968e9a80a0,82f0d8d0a486b2c8,1030103032323204 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.