Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11A2371F23684C57B8863D3D4E5293EA8BB52F32FC14C4EAD50EA110B6DC3DB4B5115AA |
|
CONTENT
ssdeep
|
768:UMq8I9YjL6f1R70Aqux2DfcosG+B9Fnz0tLVosx/XS:UDTyP+1Hx2Dfcosnz0tLVoE/S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb4f6464e4cb9919 |
|
VISUAL
aHash
|
b1003c3c281c00ff |
|
VISUAL
dHash
|
63a4594850591802 |
|
VISUAL
wHash
|
f3003c3c3c3c0cff |
|
VISUAL
colorHash
|
31002200200 |
|
VISUAL
cropResistant
|
63a4594850591802 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 420 techniques to evade detection by security scanners and make reverse engineering more difficult.