Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A23D93124D86B7B858362C8F320EB4BD39AC144E2778649F3D5871F56CAD89CCE6798 |
|
CONTENT
ssdeep
|
768:Kvz5V/1/2e5FgDItKO/rmayt0XSmwqSnbzNu9x1Bb9cj:Kvz5V9/3XgstKO/rgt8rw9nnM1Bb9cj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9414eb4aeabaa696 |
|
VISUAL
aHash
|
fd0006060600ffff |
|
VISUAL
dHash
|
71ccccccecec3933 |
|
VISUAL
wHash
|
ff0006060606ffff |
|
VISUAL
colorHash
|
130000001c0 |
|
VISUAL
cropResistant
|
000109616189014a,96d6e8b094710f8e,e01034730c033313,d0ccccccececece8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.