Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C603C6618040723F05D793C1B726A79BF7D1C149C3274706A3FA932FABCAC66EE41699 |
|
CONTENT
ssdeep
|
768:xm/eFQr48TOiZrcPB6FKMz9NWfyhAHAE9OGN7x/XnGwTZbi/z4kVudihcvUf7q:x8eFQUB6FNz9NWqOgE9f7x/XJGhcA7q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d269ad83e3a988c7 |
|
VISUAL
aHash
|
fb0000003c3cffff |
|
VISUAL
dHash
|
2369b3dcccf03300 |
|
VISUAL
wHash
|
ff0000003c3cffff |
|
VISUAL
colorHash
|
03002200180 |
|
VISUAL
cropResistant
|
2004232b23530002,cce8e8f033001000,49613193ccccf0f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 33 techniques to evade detection by security scanners and make reverse engineering more difficult.