Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16F433278E882793FF28386E25276676AB3D18550CF23CB820AF153A85FC6DC9DF21154 |
|
CONTENT
ssdeep
|
1536:I7ilWH4Ulq15rSPrEAL9x9s637yGTr7fefF/HwF:ImlWH4Ulq15rSPrEksA7yGTM6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99b162565863fa9a |
|
VISUAL
aHash
|
0f0f0f1b1ec00000 |
|
VISUAL
dHash
|
c9dadbd33020c2c1 |
|
VISUAL
wHash
|
0f0f2f3f1ff83001 |
|
VISUAL
colorHash
|
39200001600 |
|
VISUAL
cropResistant
|
7f6e5c993261cc96,3333396c8e0ce4f4,8e8ec6c6c6e7c7fa,c9dadbd33020c2c1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 46 techniques to evade detection by security scanners and make reverse engineering more difficult.