Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T135B17325B056027F0123DEE8F2C4B714D89F831EDF4A96EBF1EC819B06D6C62AD15954 |
|
CONTENT
ssdeep
|
96:RA6DCam8X83yKkek9BkPJAKgSQ1STJK7sum3hwKuG3xwM3eS3b44a35elgtkQVIu:RjD+4iy2GeJXDkFm3gG3X3v3b835+Ok0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc27338c66d926ce |
|
VISUAL
aHash
|
031b18181818d8c0 |
|
VISUAL
dHash
|
1632b2b2b232b20c |
|
VISUAL
wHash
|
1f1f1f1818f8f8e0 |
|
VISUAL
colorHash
|
31000038000 |
|
VISUAL
cropResistant
|
8004289e9e162084,1632b2b2b232b20c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.