Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1606256B681598D7722D781EDA7757B9F71D3C70ACD6316C642F8938D0AC1CA8CCAB224 |
|
CONTENT
ssdeep
|
384:xMTZ1MTvmDWeLau2HNlVURJ5l+h/UbVqKHe8/nudVdDa+7HyvE67mdK+DAzCMyjk:xM/MTvmDWeLau2HNlVURJ5l+h/UbVqKN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9b689a4a376a3a6 |
|
VISUAL
aHash
|
ffffffe600000000 |
|
VISUAL
dHash
|
08320d88555534d3 |
|
VISUAL
wHash
|
fffffffe10000000 |
|
VISUAL
colorHash
|
00006000080 |
|
VISUAL
cropResistant
|
904d32b20cc608aa,88aa55d53634c8d3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 56 techniques to evade detection by security scanners and make reverse engineering more difficult.