Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DBD223B175416EB2501F42CA609B97EB12C1F38ACF058A94D7E4075AEFF1CA1F91B364 |
|
CONTENT
ssdeep
|
192:wHB8xWRpb4gUpoupZlMess4zO7Ar3/K3XUt0J3jEoikPT+77SnmLt97cBN9cDgDk:wHB8ViessTArK3XUt01ikPToSnmZ6ct |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e712491c67364d5b |
|
VISUAL
aHash
|
00ffe7e7e7f7ffe3 |
|
VISUAL
dHash
|
69084d4d4d06060f |
|
VISUAL
wHash
|
0027c3c30703c381 |
|
VISUAL
colorHash
|
0e0010002c0 |
|
VISUAL
cropResistant
|
0c0c4d4d4d06070f,0060066969200400,4141912129c92474 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 636 techniques to evade detection by security scanners and make reverse engineering more difficult.