Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T105D138187005D67AA3B78BC0E0666E65B4B0FB4BC19454849F9C41EA0FDFEA4743E463 |
|
CONTENT
ssdeep
|
192:8Ov+50cLLPmPcmqFGFaFF0FwFkFkiFfeb4byLbu:NG+uPmPcmY0oFqW6kwfKoOu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99738ac66626dd89 |
|
VISUAL
aHash
|
0008180018181818 |
|
VISUAL
dHash
|
4412b232b2b2b3b3 |
|
VISUAL
wHash
|
001838383c3c3d3d |
|
VISUAL
colorHash
|
31200000043 |
|
VISUAL
cropResistant
|
1e0c6fcb35372763,ccecccdcccd4d5f4,2f15c88e96888ed4,4412b232b2b2b3b3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.