Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16AA29473A2102A3F219383C9F361BB2EA6D3918DC789181593F8479F4BD7E91ED1641E |
|
CONTENT
ssdeep
|
384:7Oy5NjOAVfG2QiUxWL9d5U8IIIIR54RjeIIp6EYMoywjYKjNUjqQLm5UAt9K9mCI:7Oy5NjOw5g8IIIIQRBIp6EYMDAYKN0X8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c34dbc32e11a96e5 |
|
VISUAL
aHash
|
000030202000ffff |
|
VISUAL
dHash
|
1842c4c0cbcdcd00 |
|
VISUAL
wHash
|
00f07c706005ffff |
|
VISUAL
colorHash
|
39000200038 |
|
VISUAL
cropResistant
|
0380800070908000,9c52c4c4c3cbedcd |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.