Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15272A4F37A526815205F03EFE123251CB291D6DDE2A175D4A4B8C12A1BF0DF933EE5A8 |
|
CONTENT
ssdeep
|
192:MDDTq6rF0+WwL50Q9st/l6Ydp+wix3/U9nuXet4iwDoInFEOE9jKKSTK:MDDTDdqEPuF8nSJ42 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0bc47c73b696438 |
|
VISUAL
aHash
|
c3c7c3cbc7e78181 |
|
VISUAL
dHash
|
160e1717080e0f0f |
|
VISUAL
wHash
|
c3e7c3cbcfe70100 |
|
VISUAL
colorHash
|
07000000000 |
|
VISUAL
cropResistant
|
160e1717080e0f0f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 637 techniques to evade detection by security scanners and make reverse engineering more difficult.