Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17D5387B331212436225F56DFD21F260C51C2DBC9C6E61BE9E2F441ADA6F0FA076E3685 |
|
CONTENT
ssdeep
|
768:Fd/B/yfmWDGU0gbKaV1ut+wcND/4OCRhxuvIyET:Fd/B/yfm2GU0gbrV1uEzND/4OyDyET |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
85337ac7b39c8558 |
|
VISUAL
aHash
|
00003e7e7e7e1810 |
|
VISUAL
dHash
|
f071f0d4c8e033b2 |
|
VISUAL
wHash
|
18187e7e7e7e1818 |
|
VISUAL
colorHash
|
32c00010040 |
|
VISUAL
cropResistant
|
595996b2ea264466,5ce9db1b69686971,6cc8cccccccc4d4c,f071f0d4c8e033b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 520 techniques to evade detection by security scanners and make reverse engineering more difficult.