Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C72B83094829A3B5517A0D1B7738B4E33E2830ECE13062947F943A66FCECABDD91759 |
|
CONTENT
ssdeep
|
384:MPf69kpek1wmayxqr9kpek7kaAKdzgErqHm5jUS+NpSKdzgEr1aJCU+1URF+:MPf69kpek1wmayxC9kpek7kaAKdzgsa/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e75d6c4c73194c4c |
|
VISUAL
aHash
|
00e7ffe7e7ffefe7 |
|
VISUAL
dHash
|
4d0c4c4d4d244c4d |
|
VISUAL
wHash
|
0083c7e7c3c3c3c3 |
|
VISUAL
colorHash
|
06000018002 |
|
VISUAL
cropResistant
|
4d0c4c4d4d244c4d,104461714c696946,0021ccc8d8d40900,7f6b43ce0e793321,0832301414d4d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 38 techniques to evade detection by security scanners and make reverse engineering more difficult.