Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T101321E5451D36F33C0BBC690A5B92B9913B00E9ECFF205B45DAF8387C78F959A35608A |
|
CONTENT
ssdeep
|
192:LYcPIOd9ykDhXLTU4lx7Xly+38ZC+0K4AxXI3RSfd:Lh5XDuuXI+3KDbXIid |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3933261bce6633 |
|
VISUAL
aHash
|
001818381810ff3c |
|
VISUAL
dHash
|
13b232b2b2b64869 |
|
VISUAL
wHash
|
99183c3c3c18ff3c |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
3929f5f6c6d2ea49,13b232b2b2b64869 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 189873 techniques to evade detection by security scanners and make reverse engineering more difficult.