Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T163520FE1E051ED3B071385D5A6B5AB6B36E2C349CF021A5443F843EA67CBDE08A154ED |
|
CONTENT
ssdeep
|
384:QWRHt11xEpLMzo/8YOIGXoPZ4ZdZ0ZXw8F:ht11aKzHEZ4ZdZ0ZXNF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec5992964f6591b2 |
|
VISUAL
aHash
|
ffd3c1c1f3f7e767 |
|
VISUAL
dHash
|
eb379303230405cd |
|
VISUAL
wHash
|
7f818181c1e7e727 |
|
VISUAL
colorHash
|
06200030000 |
|
VISUAL
cropResistant
|
eb379303230405cd,1918121c4cc64646 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 62 techniques to evade detection by security scanners and make reverse engineering more difficult.