Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T102B36DF1A5C0FD2301E381D7B046AA46F3BA5816F60D8D60E9A9C7C7B3D986B41676F0 |
|
CONTENT
ssdeep
|
1536:NgWaebNsqUNxWP+tLyobrECdP1pS0jD50zQ2N0msQw:NgWawNeN8P+NpSwDaVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a18b067e767d84c |
|
VISUAL
aHash
|
1e1c1c18203c00ff |
|
VISUAL
dHash
|
dcf0b0f0c0c8c1ca |
|
VISUAL
wHash
|
7e1c1c1c383c30ff |
|
VISUAL
colorHash
|
38601200000 |
|
VISUAL
cropResistant
|
e7f3f0f9317b9e96,156acac912020505,dcf0b0f0c0c8c1ca |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 38 techniques to evade detection by security scanners and make reverse engineering more difficult.