Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C12C3E0D040DC3A135785E5B7B5774F7695C784CB120A5823F4A3AA5FDAC90CE23A9A |
|
CONTENT
ssdeep
|
96:TkflriYFMSfuSTttb8v67GgqRCqgBGunFQqX4HFVGXeX/8F6ygwwgDUgijgklGR:QfRiYjjZl8iyRC5GntXkLNcllc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f43f429e42bd809b |
|
VISUAL
aHash
|
0000ffffffffff00 |
|
VISUAL
dHash
|
0c0c032ea1203088 |
|
VISUAL
wHash
|
0000fbffffff0000 |
|
VISUAL
colorHash
|
17048001600 |
|
VISUAL
cropResistant
|
0000002020200000,0c22062620223030,84012c0c0e4a3420,80609080e8888888 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.