Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19FD1A8D2C018CD3747168AD8B7F5AB5BB692C7CDD703088857F882AE96DFC60C31595A |
|
CONTENT
ssdeep
|
96:Tkf6NfPMOwG5lMOCOnzejST+ejGRwJrOSV8NnwvFuedX2HFgXEWXNX/y2ST5J:QixPZwulZ3nzeuLGa9VlAeXib |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca9525da522c976e |
|
VISUAL
aHash
|
fffffffd7c7c11d1 |
|
VISUAL
dHash
|
4f17676165492707 |
|
VISUAL
wHash
|
bf9fb90d3d381101 |
|
VISUAL
colorHash
|
07280008000 |
|
VISUAL
cropResistant
|
4f17676165492707,3d9a4c6c2daf878b,c9c9595d7d7d0f03 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.