Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T158753913D363150A667E88D8B0AB6BAA3584064DF1060AB4BBADC77E7DCF07275307D6 |
|
CONTENT
ssdeep
|
6144:meW21igBEAsUvQjn16NGuSpmk3pBtuRazO171xWBeI8Ys+hUlii8xeaHN5VkBJBh:meW21i6S73r6liE3bCnsCnp7q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac64663c3c8b9b33 |
|
VISUAL
aHash
|
c3c3ffdbdb5a39ef |
|
VISUAL
dHash
|
9696b2b2b2b2abab |
|
VISUAL
wHash
|
c3c3db1bdb1800e7 |
|
VISUAL
colorHash
|
06200018000 |
|
VISUAL
cropResistant
|
a23586b2aeabaaaa,9696b2b2b2b2abab |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.