Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ADA26331A6281E3B519782DAF3673F3A72B183C0CA46011656F943F84BFAC5AFD67584 |
|
CONTENT
ssdeep
|
192:p6PxewVgannfAv8RMA1SJ0tXyIa5UNL6MlvnliCJjIAiKTEB9lYs:2Vh4v831SJ0wu6M5nICFomg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db9ce39c617620c9 |
|
VISUAL
aHash
|
bc3c000018182c28 |
|
VISUAL
dHash
|
6971b254b371585b |
|
VISUAL
wHash
|
fd3c18003c3cfcec |
|
VISUAL
colorHash
|
38400038000 |
|
VISUAL
cropResistant
|
66162eada86bb92a,261665ae5931ead3,fefef2cdcdfbfefe,6971b254b371585b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11545 techniques to evade detection by security scanners and make reverse engineering more difficult.