Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FC23413001431F3FA567C7F5B575732423A6D75DCAF382689AAE136297CBC919F22284 |
|
CONTENT
ssdeep
|
768:wPYP8RBHjMBAd6I9uszZexZ8oqr8tC27fpg+6/XIid:8JHj+czZieVAvFg+6/Xd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c3ca4a633e63671 |
|
VISUAL
aHash
|
5f19181c003c7cfc |
|
VISUAL
dHash
|
d63330697060c0d0 |
|
VISUAL
wHash
|
5f1b181c083cfcfc |
|
VISUAL
colorHash
|
3800020001b |
|
VISUAL
cropResistant
|
d63330697060c0d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 189502 techniques to evade detection by security scanners and make reverse engineering more difficult.