Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A273533179105836826743D5D1788B16B2A2F706CA031BC9B3E4C3BE5FC6DB5FE26269 |
|
CONTENT
ssdeep
|
1536:68GxnXredhyQEtotG4034pGgIh4Y94My4dr7CPr7+r7xr7Wr72r7+r7q4/CC141A:68GBed83EGgUF95yGHCH+HxHWH2H+Hqi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d85236070dbdbd9 |
|
VISUAL
aHash
|
47033f3e18000000 |
|
VISUAL
dHash
|
8e36727010301000 |
|
VISUAL
wHash
|
7f073f3f1e18003c |
|
VISUAL
colorHash
|
38000006000 |
|
VISUAL
cropResistant
|
8e36727010301000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 868 techniques to evade detection by security scanners and make reverse engineering more difficult.