Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T195B3533562450B3DA58BC2D5FB64BB28915ED347C32BAC5DF6F542739A02C18EC272E8 |
|
CONTENT
ssdeep
|
768:yc/kL6x+98OuKcSZ7viJBJBse+fZHzaDbcduhsty0gKIBKen8QT/rifyzJZl2V1W:5Mg/2c4GpiTa+V1/0J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c243becb4c63bcc1 |
|
VISUAL
aHash
|
00000000ffffffff |
|
VISUAL
dHash
|
69c8dcc8e0103826 |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
8601614949610040,e0801322c0203126,0021485048081200,30c8c89848dcc0e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.