Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T191225133B500DE1A4D9B5688F5C49588452EC346FB3148C7B1A490FF7BD1DF0AAA93AD |
|
CONTENT
ssdeep
|
96:DyCraR1sYs+tnt1fBDCS+LwSEt4xFlqGMcnthWeNWb1fMmORR1E8VConv55svCLl:DadsOyi4xFZMcnthWeNWb1fMmUU8VCoT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6e6996e99e411e0 |
|
VISUAL
aHash
|
f0f0f0f0f0f0f0ff |
|
VISUAL
dHash
|
2664a42466a70727 |
|
VISUAL
wHash
|
f0f0f0f0f0f0f0f0 |
|
VISUAL
colorHash
|
0e000000038 |
|
VISUAL
cropResistant
|
2664a42466272727,9282f03a3bea849a,ecb3f078f9fdff7f,0000243432320c10 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.