Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F8D130F1D044ED37035386DAB7FA6B4B76A1C349CB030A4453F883AB5BDAC60CB25699 |
|
CONTENT
ssdeep
|
96:TkdcnbzD71tDlt8v67MzddtG9XmwvFsehXsHF0eJXMX/gSh2J:QdcnbzD715lt8iIJdo9X3qp2XThw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8b931b14ec647c6 |
|
VISUAL
aHash
|
cfcfffdfdfffff00 |
|
VISUAL
dHash
|
9a9a003030400000 |
|
VISUAL
wHash
|
c0c0c0c0dfffff00 |
|
VISUAL
colorHash
|
07c00030000 |
|
VISUAL
cropResistant
|
9a9a2030b0002000,01c96969c9f4f401,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.