Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D0F2026070001F76275B69D859719B4732E2D242DF8B3D49C6DA63E767EACE08C7E0B2 |
|
CONTENT
ssdeep
|
384:S4Bs/HmfXxgfc0X1bnPzI/eLyww2sVkHdXl+GuU9uyW4jyW4qyW4FyW4whyW47yh:nBs/HmSc0X1bnfSVYTPznB0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8b84ec638b919c7 |
|
VISUAL
aHash
|
ffffdfcfffffff00 |
|
VISUAL
dHash
|
3020109400100030 |
|
VISUAL
wHash
|
908080c0ffffff00 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
2030109400100028,0460790832320800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3786 techniques to evade detection by security scanners and make reverse engineering more difficult.