Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E4241A49E9861A13367CB7DB0A46FDCB26A611FC733A054F3D8574483CAEB9CE44385 |
|
CONTENT
ssdeep
|
96:5RpnY1N4TQvQKuiJeSMzAdyNc7JHrGPPbkcxz2PTeiwDsK73Mr/x/BDXgtHnPJZ7:DTQrn9RmwLwVl3lj+Mocfk7y7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dcf3201c39dbcb03 |
|
VISUAL
aHash
|
18c0fcfc10b8d040 |
|
VISUAL
dHash
|
700cc8a8742121b0 |
|
VISUAL
wHash
|
18e0fcfc9cbcf840 |
|
VISUAL
colorHash
|
32000010003 |
|
VISUAL
cropResistant
|
12100a81e9c7e969,700cc8a8742121b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 486 techniques to evade detection by security scanners and make reverse engineering more difficult.