Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3B2963432941A7FA1C7C7F1E770377EE1A5C78ACA179A09F2E982595BC2C48CC563A0 |
|
CONTENT
ssdeep
|
192:zD5hyTMzgE9Rn3RsLqmwAz1Waz4/CrnMDkjCJz4CHgkEY5QZrgZtT+:p7913mnwQz2B/bogZtT+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fb3bcc50e168803f |
|
VISUAL
aHash
|
ff0001646e0480ff |
|
VISUAL
dHash
|
396949d9dc8d2134 |
|
VISUAL
wHash
|
ff8001e4ec2c90ff |
|
VISUAL
colorHash
|
06c03000000 |
|
VISUAL
cropResistant
|
39393038393b6969,38bc66767c7cfcfc,226ba1b46c0494a6,12928ca6a4a8cc04,3424342455545534,386959c9dcdc2930 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.