Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12C93D631A008367F110356EAFA22A328136DA36FF71159A8567D03B4F6E7CF8D673169 |
|
CONTENT
ssdeep
|
768:3h08pyMuFDt5VsoQFV2jBq7MAEmM2/DXtLnfb4uQGu5udRMih:a8pykjFIVmM2/DXtbow |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9973cc6664993399 |
|
VISUAL
aHash
|
12104d0030423d48 |
|
VISUAL
dHash
|
26249a1464043a12 |
|
VISUAL
wHash
|
13030f03e3c3ffc3 |
|
VISUAL
colorHash
|
00000000007 |
|
VISUAL
cropResistant
|
4eb2726e1a65e4a4,1e1f57641c657959,26249a1464043a12 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 302 techniques to evade detection by security scanners and make reverse engineering more difficult.