Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1400248E19400540B021782CA65937B4D3483F3875F661C556AE943ABBADFBF0A8FA3D7 |
|
CONTENT
ssdeep
|
96:T84T4XmBB5BeIR1J4EDsJsZdSdaHYiAin3AWCMXI6npARnuAixuzAWC5VA6xyAR6:ACBXoiwQHYe5BiqBBJ3oz3NWHP+SA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b099c766dc339934 |
|
VISUAL
aHash
|
ffc3cfcfc3e7c3ff |
|
VISUAL
dHash
|
16161e1a960e0c08 |
|
VISUAL
wHash
|
03030303c3c3c3e7 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
16161e1a960e0c08 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.