Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A12C67120111A7F4553CAE5B162B778E4EFDB0EDA1B8C79F2BC02570BC5D948A22792 |
|
CONTENT
ssdeep
|
192:b4ATpZu4MTAQYo5LArr6Lm17CYX9XHL/OtZDvbHxfQ3II0V+OIYLU:3TXu7ZJ5LAf6La7LCvbRohVb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212ed6dd9ea1296 |
|
VISUAL
aHash
|
fd0406060400ffff |
|
VISUAL
dHash
|
23ccccccccfc2726 |
|
VISUAL
wHash
|
ff040e060600ffff |
|
VISUAL
colorHash
|
130020001c0 |
|
VISUAL
cropResistant
|
048b6b2b2b2b004c,daf8e2b280311788,7b242c2424666686,2010626169621000,4cccccccccccecf7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.