Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1912230B06259CD3B6067C1E1E7BA572B32E5868ACD4B030593FD83E89FD6C85FC26154 |
|
CONTENT
ssdeep
|
192:/cwXce18OvNDMDIvM3cV0fPOfytJtpOeq4b1tL+OzyZJ:/cKce1tptiufytJtpJq0tL+OzyD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b33399992363c933 |
|
VISUAL
aHash
|
ffe7c3c3c3ffffff |
|
VISUAL
dHash
|
584c0c0c0c20180c |
|
VISUAL
wHash
|
c4c4c0c0003c3c00 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
584c0c0c0c20180c,4141414141414141 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 88 techniques to evade detection by security scanners and make reverse engineering more difficult.