Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6F124E1C048DC37431386D5F7F56B5F75D6C349CB02098853F852AB5BDAC60CA2669A |
|
CONTENT
ssdeep
|
96:TkZZfbK7mohOhHWfeG4VT8WB1LGCwvlReZX1HlGeRXjH/NplX5u/BwNmDECHxBQR:QjbK7mohOhHW14WWBZGUPjZzzueeQR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac6c6ccccece8293 |
|
VISUAL
aHash
|
d3c3cfffffffffff |
|
VISUAL
dHash
|
a69e9a342c4c1008 |
|
VISUAL
wHash
|
d3c3c3ffc7e70000 |
|
VISUAL
colorHash
|
07000000183 |
|
VISUAL
cropResistant
|
a69e9a342c4c1008,80404028108c83f0,d4e263694d494dd1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.