Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15DF10FF1D004ED3B035386D9B7B66F4BB691C749CA030A45A7F883AB5FDAC60CE11599 |
|
CONTENT
ssdeep
|
96:Tk7bzD71tDlt8v67MIdwuSS8ctUenFaJkXCHFhRXIX/wytF6fq2J:Q7bzD715lt8iIywUGf/yXYy/aqw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4e4139b1bec1393 |
|
VISUAL
aHash
|
f3f3f3f3ffffff00 |
|
VISUAL
dHash
|
262626a630400000 |
|
VISUAL
wHash
|
f0c0c0c0f0f0ff00 |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
262626a626002600,fef833fce869dc7e,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.