Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1210454B08264AE6E4553B3D8E431B76F722162E6DBC70BC897F0A356B95DDF08C090D9 |
|
CONTENT
ssdeep
|
768:5goKLc0vIyNb+xsJ0qGUSY3A7wZK2/kJaueIFY6zjmIRLS79Jo2o52T784ci+hCV:Ic0vIyNb+xIGFReP/95OqYS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ceb33cacc226636 |
|
VISUAL
aHash
|
010800189c180002 |
|
VISUAL
dHash
|
131014b232301416 |
|
VISUAL
wHash
|
011f9b1b9f9f0e06 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
131014b232301416 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 427 techniques to evade detection by security scanners and make reverse engineering more difficult.