Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17CA22A2FE6C024461E871251BF41BEA7D93C4E5C9735A150ECF9828B63B4CA4D1BB2F9 |
|
CONTENT
ssdeep
|
384:tHVPBRQb7GuXkD4lOs+snxIlWr/5BSQ2VyZO5nXTlFn1WdrjSjU+Df:tHVPBRQb7GUkDmOvk58Q20O5Dn1q6f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94947763696947c6 |
|
VISUAL
aHash
|
661e3e1b383c3020 |
|
VISUAL
dHash
|
d4f4fcb2e0c8d0c8 |
|
VISUAL
wHash
|
661f3e5f383c3c20 |
|
VISUAL
colorHash
|
30000440010 |
|
VISUAL
cropResistant
|
d4f4fcb2e0c8d0c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.