Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T192534A31B6317C3853EB48EDB37D6A46A1C2C908D9C64940F7D82A9D67C7CB632467B8 |
|
CONTENT
ssdeep
|
1536:a0YZW+Ty3MTjm6MT4nne6ejaeeDt0M7BCtJM7BgYWM7BGYrM7BUC7UXx+y9dQyD1:apkMTVMTOtUtTYiY07UXxpDzHyC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e7664e646ccccc64 |
|
VISUAL
aHash
|
42e7e7ffc3e7c3ff |
|
VISUAL
dHash
|
06080c100c0c2b07 |
|
VISUAL
wHash
|
00e7e7c3c3c381cf |
|
VISUAL
colorHash
|
07006000040 |
|
VISUAL
cropResistant
|
06080c100c0c2b07 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 223 techniques to evade detection by security scanners and make reverse engineering more difficult.