Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B913E9207840D92705CB69C96637272A62F6C308CA234699FAB5D7F91FEFD68DE37110 |
|
CONTENT
ssdeep
|
384:j3sJO5xVZjqTSO67Ja0+sYKNWKDnCwKgoKnoSQKYHnynvINDtQmEMhSZbZ0roUa+:jsIx/j17t2j0nRYRlHyvSDt8tRUf79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94ebcbb4e534340b |
|
VISUAL
aHash
|
fffd02070706067f |
|
VISUAL
dHash
|
6679ec8eaeacfcf4 |
|
VISUAL
wHash
|
ff7e0606060606ff |
|
VISUAL
colorHash
|
0b203010000 |
|
VISUAL
cropResistant
|
00004064f4c00059,a1e9ded1a981b3b1,f4f4004202000000,00034baba2160601,f9ecaeceacacf4f4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.