Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17343FAF97952FA235AB251E700AF2407333CA52B640C8DB0E251EFD965B8469507FF8E |
|
CONTENT
ssdeep
|
1536:RYpzQcmiT3qFDNJa/V12DZHv9HdbSstAOOdg+Njg:YTKNJaP2DFv7bSeEdg+Njg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b1931e8cca6d963 |
|
VISUAL
aHash
|
0f0f0f1f1f1f070f |
|
VISUAL
dHash
|
9a5a797de97dadfd |
|
VISUAL
wHash
|
0f0f0f1f1f0f0707 |
|
VISUAL
colorHash
|
06006000040 |
|
VISUAL
cropResistant
|
f27472d2d5f3b4f4,cb1b3b7cfe9edcf7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 865 techniques to evade detection by security scanners and make reverse engineering more difficult.