Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E10272E2C054DD360B1285C5B7B5776FBAB2C304CB020D9453F853BAABCADA1CB125AD |
|
CONTENT
ssdeep
|
96:TkGGzHwLTSTaKUEdt7fkwvFlQepX6HFaetXKX/8hSTu1+GAT43a:QGGzHwLeDUEdprUDEXB61M8K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b1a7da41d6941ae |
|
VISUAL
aHash
|
010d0d0d0f6fffff |
|
VISUAL
dHash
|
3b195959b99e9e58 |
|
VISUAL
wHash
|
000d0d0d0f6fef6f |
|
VISUAL
colorHash
|
06600000080 |
|
VISUAL
cropResistant
|
3b195959b99e9e58,52d25a525252d2c4,02a0021213136380,2f2c6c27b7b76ef0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.