Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B11254708058DD2BD0D3E2E8A6B0975F1AA183EDDB0B0E5216E88F1E5EDBC40DE153E5 |
|
CONTENT
ssdeep
|
96:thhKkDhKIhSJjJULdseEGp41x2QYWtKk2igoB5cJgQADtkdK0hK0FK0HK0ZK0W4c:tmbPwLieEQ+x2QYAvLB5caQAxkAA8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8955265d897726dc |
|
VISUAL
aHash
|
0000183c3c180001 |
|
VISUAL
dHash
|
a00c32b2b2330c21 |
|
VISUAL
wHash
|
00337c7c7c7c7f01 |
|
VISUAL
colorHash
|
07000030001 |
|
VISUAL
cropResistant
|
c2383a82bcb282a4,a00c32b2b2330c21 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 38 techniques to evade detection by security scanners and make reverse engineering more difficult.