Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A53361F0C0E19A37019381C06DB5EB3BB3D54285ED8307591AFD835E9EEBE05EE25689 |
|
CONTENT
ssdeep
|
768:0knPqo6hnHZjIsRFj44u60w6Iga/LDbwZJidUsZqzy42/n6gHwKOpLhBXgR7V:0Y16/XRFj44u6YIgUL/wA5PHQQ9V |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba4bcdce331a4253 |
|
VISUAL
aHash
|
fcff8787878f8f87 |
|
VISUAL
dHash
|
21260d3c3c2c3c3c |
|
VISUAL
wHash
|
38d3878787878787 |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
21260d3c3c2c3c3c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1079 techniques to evade detection by security scanners and make reverse engineering more difficult.