Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17E33B5711151AB7F5287C3E4B3A0BB19A38DC295CD9B854AE3F582C92BC7DE6CE02644 |
|
CONTENT
ssdeep
|
1536:D8A+4kAZt3/QoqdWIk4uULGFy3jEIBh8II03jsBa9D7Qq4ym:D8A+4kAZt3/QoqdWYLrIcm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee53b91469944b3c |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
d0c8d8c781d8262b |
|
VISUAL
wHash
|
006c3c0000ffffff |
|
VISUAL
colorHash
|
0a000000007 |
|
VISUAL
cropResistant
|
c2212933232f0b23,92c9c8d8e4c78bd4,9e0c268260707a6c,0fa22a244c59acac |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.