Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19A92A5F55248FBB6508383F0E632A36E32E280DDD74356158BF48B86E9C5CA9CC51AD6 |
|
CONTENT
ssdeep
|
192:QKyXCbLQ6mq0Rq74IrnErmugvugajT+X9WjUxYUxzQVEEhCCbLQ6mqbiGFx:hyXLU0RqMIv3v3Y29yUuUBnMCLUbi0x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9c362c9e162c9d9 |
|
VISUAL
aHash
|
7e18000018180099 |
|
VISUAL
dHash
|
d0323054b2b20c33 |
|
VISUAL
wHash
|
ff3c3c3c181800ff |
|
VISUAL
colorHash
|
38200030000 |
|
VISUAL
cropResistant
|
fefffbcdcdebfffe,d0323054b2b20c33 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.