Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17754C9703261223F405B0BF5A170761183DDA258EBDB95ACE64D6372F3E7CB2A6D29C4 |
|
CONTENT
ssdeep
|
6144:3KrmgXQ0z7w1zBpzuFaoy35FV7HjDCo+qPtSoHuPCCoWpP2itz1PW5jw3PU6M1LG:YmgXQ0z7w1zBpzuFaoy35FV7HjDCo+qW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb3caea3a88d8b23 |
|
VISUAL
aHash
|
c380183c2c2c3c3c |
|
VISUAL
dHash
|
07057171c8c8c869 |
|
VISUAL
wHash
|
e7c1003c7c7c7c3c |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
07057171c8c8c869 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4287 techniques to evade detection by security scanners and make reverse engineering more difficult.