Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T102B13432A201963D5D434A40F759FB79F298AA19CA499A9D74FC02D22EDBFF8CA05701 |
|
CONTENT
ssdeep
|
96:TGQX706oBChswpuLW/e7Hd6M6j6a6Z6o6/6W67z+nZIaOlWKYme:l70YhO9pqzctOnFnMYj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dda62699c98dc866 |
|
VISUAL
aHash
|
fffffcf8f8980000 |
|
VISUAL
dHash
|
0008083030300000 |
|
VISUAL
wHash
|
fffef8f8d8980000 |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
0008083030300000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5362 techniques to evade detection by security scanners and make reverse engineering more difficult.