Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D52B672814948339463C5E4F7DEE6298365A158CF8299C4E3B882BDD3C9C70773AADC |
|
CONTENT
ssdeep
|
192:MEksdf2T9gbwG9q1yqjWdEayU7tqYtYP6b7eCDn7G8Rm4gtGJhK:LksdWhyqjW6ahtYP+tRmntl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c92936969963c |
|
VISUAL
aHash
|
c3c383c1c3ffffff |
|
VISUAL
dHash
|
92372ba2964d4c4d |
|
VISUAL
wHash
|
8180818181fffffe |
|
VISUAL
colorHash
|
06c02000000 |
|
VISUAL
cropResistant
|
92372ba2964d4c4d,401860796969922c,c64795c7d7d6d684,f353fafebede3e6e,ac74f25231114100 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 642 techniques to evade detection by security scanners and make reverse engineering more difficult.