Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10891B62160B42F7B0153ABE4B391AF56F3D8F345C55BCB28A2FC8209A3DDCC0E805618 |
|
CONTENT
ssdeep
|
96:ANv44AMuzClkcpIf76qnPFtaI6zPVK8ZZHTjwU3We22:AV4MT9pO6aztMPVf9Ts222 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e69966996699338c |
|
VISUAL
aHash
|
e7ffe7e7e7e7e7e7 |
|
VISUAL
dHash
|
4c484d2a4c4d2c2d |
|
VISUAL
wHash
|
e738040407072727 |
|
VISUAL
colorHash
|
07400000180 |
|
VISUAL
cropResistant
|
4c484d2a4c4d2c2d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.