Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19864F9B5832402749ACF17DCE8D13916142598EBE5743BCC972B05B0BDE2EE598F26CE |
|
CONTENT
ssdeep
|
3072:Aj26BRqXmIAfS581eb090jrOB2euxqxWW8yq9LP/4+pviiiXjozow:Aj26BRqXmIAfS581eb09ibp+ozow |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc18c3ce32c3c3cd |
|
VISUAL
aHash
|
998b898783e3ffe7 |
|
VISUAL
dHash
|
2132122e2f0b030e |
|
VISUAL
wHash
|
918a818383c3ffe7 |
|
VISUAL
colorHash
|
07000030000 |
|
VISUAL
cropResistant
|
2132122e2f0b030e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 486 techniques to evade detection by security scanners and make reverse engineering more difficult.