Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1841395F2A508327B2247A3D5771AF31277818009CF8366D6F3FDC29D9BC6D91D8A164A |
|
CONTENT
ssdeep
|
384:vHpJ7Ck/IeVerPhJ2Mvyc6Lk+0WB6ygDFUFl1Co0+CJrAh0B6zk+nWB6cygRKky/:SyIeVerPhJ2hhk+iZxdZG82cul |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
80d17e38c3d7d8cc |
|
VISUAL
aHash
|
7f5f7f6763430311 |
|
VISUAL
dHash
|
d1b6c6cac697d7d7 |
|
VISUAL
wHash
|
7f577f6363410301 |
|
VISUAL
colorHash
|
06e40000000 |
|
VISUAL
cropResistant
|
d1b6c6cac697d7d7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.