Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T118138421E2301E3A508FF3F0E2556BC692A39393CBD217C0E2DDA7495BDACA1974365D |
|
CONTENT
ssdeep
|
768:wq6oDhXYAIjncn5n6Hewa+JwyHwUOnw7djncn51sDGDPh2exeewYpwLyD0:V6oD2ewa+JwyHwUOnw7BDGD52exee30 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
911b0d3a335d5c76 |
|
VISUAL
aHash
|
00ff7e66667e7e7e |
|
VISUAL
dHash
|
bb72cccecc9ad292 |
|
VISUAL
wHash
|
00187e66665e7e7a |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
bb72cccecc9ad292,23c42b9b1b1b0b83 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 389 techniques to evade detection by security scanners and make reverse engineering more difficult.