Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C65A5A54328D39C698BC55DDF37E9A0571F90EAF2BA92D489EFC774A04B8C0F503864 |
|
CONTENT
ssdeep
|
12288:GFjvimA/Yh4+vRhNSfmAaE1mAjEzTmy/PWK4:GSJbF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb439ef886b034a7 |
|
VISUAL
aHash
|
fcf0e0f0f0c0f9fc |
|
VISUAL
dHash
|
c0488a8840113161 |
|
VISUAL
wHash
|
fce0e0f0f0c0f0fc |
|
VISUAL
colorHash
|
0e003000041 |
|
VISUAL
cropResistant
|
c0488a8840113161,b989d9b0369a9731,0042484041202003,444dc1010206070d,5d5d4d4d0d0d0d21 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1804 techniques to evade detection by security scanners and make reverse engineering more difficult.