Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12EA2C632A1112A3F12A7C3C87762B72EE1D3D289C78D181983F9479E4BDBE50DC2655E |
|
CONTENT
ssdeep
|
384:TOy5N/ynH/Vr2IGKbMTM2HzIIII75emIITyHYMe1Mj2pjqUjqniy3G0vAmfCEIYN:TOy5N/ynHPezIIIIclITyHYM082Fq003 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c347bc3ae13296c5 |
|
VISUAL
aHash
|
000030202000ffff |
|
VISUAL
dHash
|
9c46c4c8cbedcd00 |
|
VISUAL
wHash
|
00f07470600dffff |
|
VISUAL
colorHash
|
39000200038 |
|
VISUAL
cropResistant
|
0380800070908000,9c12e4cccbcbedcd |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.