Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12A22B7B19048092F921307C9E350F3B663F5D1B2E7450605E9F88B6E9BD7E86EC974AC |
|
CONTENT
ssdeep
|
96:dUA1hTNKaKseb9HF6MRgTaT+NhZEYZJ4QKQqQyQONQSQO4wNCG1xhAlUwixEeBaM:dUmh8xseb9l6MBT+B2JAlOuLM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8b090945e3f3d9cd |
|
VISUAL
aHash
|
00003fffffffffff |
|
VISUAL
dHash
|
f0f371088c160000 |
|
VISUAL
wHash
|
000018e7ff00ffff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
a280a2e2e2a280a2,716908584c4d1608,0e3c080000000000,f0f09ffff3f7f171,0080909090804000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 188 techniques to evade detection by security scanners and make reverse engineering more difficult.