Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11BA2C733A0542A3F515783CDB352FB6DA1A39349C79A0C0552FC4BAE8BE3E90EC1755A |
|
CONTENT
ssdeep
|
384:GPAy5NbGgerLSa4ARi9vWx+QcivZb9NPZLo/EvsDPMIYsOy2+y9BH4cUUIe:SAy5NbreJWLQcivZbLZAEUA7sOy2+y9j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c367dd12924d6d92 |
|
VISUAL
aHash
|
000020000400ffff |
|
VISUAL
dHash
|
1c4b434bcd337000 |
|
VISUAL
wHash
|
00f1f1210f00ffff |
|
VISUAL
colorHash
|
39000400002 |
|
VISUAL
cropResistant
|
0000000d0d010101,0080900270b08000,1c494343cdcd0770 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.