Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T171B12FB061286A7653AB46EEE850E73DF7E7834CC53BB94523ECE74617C4E68D802162 |
|
CONTENT
ssdeep
|
96:gUs/lYj1kgrmhKPK52RbMpakn5hJS61dlpIFd4QXAbZ9AbZTAbZEjdTZasbQ6FbZ:gB/lYj1zPKgMp7DfU+gz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93266cd266c6999b |
|
VISUAL
aHash
|
000c3c3c3c3c1c08 |
|
VISUAL
dHash
|
6cf8f8d8d8f8f8f0 |
|
VISUAL
wHash
|
001c3e7e7e3e3c1c |
|
VISUAL
colorHash
|
18003200000 |
|
VISUAL
cropResistant
|
ee969a8ef2969a93,6cf8f8d8d8f8f8f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 306 techniques to evade detection by security scanners and make reverse engineering more difficult.