Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BD024735505A26371B1B0BE6A66957BEB1F18A0ACD7B30A027FD93900FE5C548D1FC1B |
|
CONTENT
ssdeep
|
192:3aBAqBtXqBCqBi/qBlqBwCqBAaqBpGqBbUqBHPqBSAqBvqBuaqBsqBDqB1XqBRZp:3aB7Bt6BVBiiBoBwVBAtBpRBb3BHSBSP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9276294d2ed53ad1 |
|
VISUAL
aHash
|
0004ce8e00007e01 |
|
VISUAL
dHash
|
6398981c06d4d4c3 |
|
VISUAL
wHash
|
80cccece007e7e3d |
|
VISUAL
colorHash
|
38006000600 |
|
VISUAL
cropResistant
|
6398981c06d4d4c3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.