Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10A8383A842504437819389EB6631574E229DC208C707BE959BF483DBBFCAEA5DD0778F |
|
CONTENT
ssdeep
|
768:QLHHUIH341D00T3OKMIYkYIe5UDjaZfoUCCNDID8fe+P8eURHLAL+ixr1zR7Duub:usUCCN482e8eUdASCpd7DoI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95ada96c523d9545 |
|
VISUAL
aHash
|
1b1f0f0e6407070e |
|
VISUAL
dHash
|
96555e9c8cc69e1c |
|
VISUAL
wHash
|
1b1f0f0e76470f0e |
|
VISUAL
colorHash
|
38011600000 |
|
VISUAL
cropResistant
|
393b3698c1f3f9de,be3e364d4d0c3abe,3e364e4c4c3e3ebe,be3e324c4d4c323e,96555e9c8cc69e1c,5153436f6e3e1c1c,e183ce8d1a3c7871,3c78e38409100307 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 44759 techniques to evade detection by security scanners and make reverse engineering more difficult.