Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T106E175E1C504DD3B032286D5F7F52B5FB9A2C359CF06498493F842EB9BCAC60CA1669D |
|
CONTENT
ssdeep
|
96:TkG279oh4lzH0XfeGiEdt72qDwvFVelX1HF3exX8z/Ht7pYqQPJ:QG279oh4lzH0X1iEd4qxH8WzfjYqQR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4c669db5972126c |
|
VISUAL
aHash
|
00e7c3e7ffffc3c3 |
|
VISUAL
dHash
|
0906861622000f17 |
|
VISUAL
wHash
|
00c3c3c3ffff8181 |
|
VISUAL
colorHash
|
06000000181 |
|
VISUAL
cropResistant
|
1606861622080717,090909090c090909,841c316ff0e37b33,4d999b9b036bca93,6666a6a6b4b0b0b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.