Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12DB30A3BD358023E32AB47C5B7543B9CB692504EDBDC0AE6E06BC14D63CAD516633AC6 |
|
CONTENT
ssdeep
|
3072:ucPCI2/Os81G3FOROpUJwnMOqKb0IheRO/p8tUwOkDDH9jIrjgS5ybkOQTrGkGpI:ucKI2Gs81G3EYpUJwnHqKb0IheY/p8t0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc3947631c3c3e43 |
|
VISUAL
aHash
|
00ff9f9fffe7ffff |
|
VISUAL
dHash
|
6b4a3b3b1b0f2d27 |
|
VISUAL
wHash
|
00838b8bef83e797 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
2b0a3b3b130f2d27,0068704f4b726040,06d1632e2e63d806 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.