Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7F394607B12A436216FA2CFD2376B0C61C3D7CFD5D117E992F84264AAB2CA03AD35D5 |
|
CONTENT
ssdeep
|
1536:JpkGvXIBpHlz4Z/z7LWAd+HDmYhBBJi3MREJEHXMbg8MoSzJ8r/Ub5MJS16eCswd:0mKpU/+mYhXJi32EJEHXMU8NSV8jUbA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9c363733339c86 |
|
VISUAL
aHash
|
061818183c180000 |
|
VISUAL
dHash
|
d4b0b078f07054d4 |
|
VISUAL
wHash
|
7e3c7c187e3c0c1a |
|
VISUAL
colorHash
|
38001400040 |
|
VISUAL
cropResistant
|
b07066e3da8ce468,f0c89b93c6f63c58,d4b0b078f07054d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 704 techniques to evade detection by security scanners and make reverse engineering more difficult.