Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17D738336B3000F769A179BE8F513D750427ED32CD94292ACD72DD232C9E28EBE5AD506 |
|
CONTENT
ssdeep
|
1536:C6V6ecivym6x+4+C+r+3+W+6+T+H+2+T+w+z+1+j+A+7+V+D+X+p+8+i+j+P+m+4:q2d/N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c362b93c3c9e62c6 |
|
VISUAL
aHash
|
006074243000ff7f |
|
VISUAL
dHash
|
d4c8cdcdc4d0f0ca |
|
VISUAL
wHash
|
406074747404ffff |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
d4c8cdcdc4d0f0ca |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 189680 techniques to evade detection by security scanners and make reverse engineering more difficult.