Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16F23842233451F7ADB23DFA4B4139F8041BDD71CCAA2A06CD66ED227C9E7C97926D205 |
|
CONTENT
ssdeep
|
384:dC2scXjLOapqZ5yErChijoGU+AKH8B4gOTDp8iR+K4t/TXI+3KDbXIid:DOvy/GUY8Mvp80Ihk+6/XIid |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8fd8c73061e499cb |
|
VISUAL
aHash
|
7c3c3c1808063733 |
|
VISUAL
dHash
|
d0f0f0f0796d6d4f |
|
VISUAL
wHash
|
7c3c3c1c1c073737 |
|
VISUAL
colorHash
|
38001000180 |
|
VISUAL
cropResistant
|
d0f0f0f0796d6d4f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 189678 techniques to evade detection by security scanners and make reverse engineering more difficult.