Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T197339AF793648B3E51934394CB71B3BA31D78188CE0E47359BF993249A96D8ADC360D8 |
|
CONTENT
ssdeep
|
192:fMQ7nr774PEDkCDhFKYShVTBA5BVmd3FY7ZjrohgxR1c6Xx:fR74QkCmYS5Arods+hy1cY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc393f7676632260 |
|
VISUAL
aHash
|
801819f8f8f8f818 |
|
VISUAL
dHash
|
2a32b3a2b2b2b2b0 |
|
VISUAL
wHash
|
80999bf8f8f8f818 |
|
VISUAL
colorHash
|
30000e00000 |
|
VISUAL
cropResistant
|
2a32b3a2b2b2b2b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.