Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10D6321B5130110AD66D7FAE0F1917F5B91BACADAE50F6E9CB1BC08652FC1FA4C8D1290 |
|
CONTENT
ssdeep
|
768:CA+pZiO5NgIf6+0gFw8kgxgoo3YoD+J41i94lGHJ:CA+pyonxgooooD+Jz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95b1683cb5b1b469 |
|
VISUAL
aHash
|
03016f0e0e2e0000 |
|
VISUAL
dHash
|
bef7ccccccecc180 |
|
VISUAL
wHash
|
030f6f6f3e7e20c0 |
|
VISUAL
colorHash
|
00000e00000 |
|
VISUAL
cropResistant
|
88888a888bcb8888,a28234bc5141989a,ba795cd9d9dcccca,bef7ccccccecc180 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8808 techniques to evade detection by security scanners and make reverse engineering more difficult.