Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C492D590780A4A2E972BCCC8410BFE22B556F385DD4DA894B5D271E32FD7C64229D1FB |
|
CONTENT
ssdeep
|
192:KyNKVe2PpbrxROoZ2uUOgWssDMlWOQU2OAGMguuUAEhMgOkcvqsug5WQukgjkQ6W:nNKMKIwx7g/Ux7g/nZNI1NR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2d931468966ce67 |
|
VISUAL
aHash
|
fcccfcfcfcf4a0c0 |
|
VISUAL
dHash
|
10181820386c0c12 |
|
VISUAL
wHash
|
f8cce0fcfcf480c0 |
|
VISUAL
colorHash
|
07006000000 |
|
VISUAL
cropResistant
|
10181820386c0c12 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26339 techniques to evade detection by security scanners and make reverse engineering more difficult.