Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T165321A355040BA3795D3A2E1E7351B6FB3C4868ACA130B45A7F4878D5FD7CA4CC6264B |
|
CONTENT
ssdeep
|
192:/p8v+CYQN+9+RcrDU+VgLHnrwwdSECsHkoQNXT+aSf/:/iqxVerww1HkUaSf/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93d12c6cb2d1c3c7 |
|
VISUAL
aHash
|
66007c6e00180025 |
|
VISUAL
dHash
|
d4e3d8d88c33c8d5 |
|
VISUAL
wHash
|
66087e6e0e183c7f |
|
VISUAL
colorHash
|
38002000180 |
|
VISUAL
cropResistant
|
d4e3d8d88c33c8d5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.