Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF93677522985732832BAF8885652AB42357646E8FD380327FDE0363C3B7ED4CD952C6 |
|
CONTENT
ssdeep
|
1536:yyeIFW3ghABN11tmU7lUjIvRsumJu7ugL8PN11tmU7laX+6/Xs+6/Xd:pWN8u7ugL8jY/K/N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dd2222dd23719d74 |
|
VISUAL
aHash
|
80103c2c18bc9881 |
|
VISUAL
dHash
|
086955497232300d |
|
VISUAL
wHash
|
ff343c3c98bc9881 |
|
VISUAL
colorHash
|
38000000038 |
|
VISUAL
cropResistant
|
086955497232300d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 189680 techniques to evade detection by security scanners and make reverse engineering more difficult.