Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11B33337179626539309F72CFC227170D62C3E7CAC7926BE685F052249AF5C94BEE3284 |
|
CONTENT
ssdeep
|
384:8FGYzr0egtqe6xnN60i5y+4OJDBzzye6z/aPMkHMnxGJToPIzr/4477U8yUyD6Du:8yegts60icGr0YPAyd77f5fxLNbOZl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
962d343d16679617 |
|
VISUAL
aHash
|
000c3c3400ffff2c |
|
VISUAL
dHash
|
d4d969699923cccd |
|
VISUAL
wHash
|
003e3c3c0cff647e |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
1b1b5454a5e42b2b,f0e8cccececc7197,02c00b2b2f2bc000,b3bc3cfcd2929292,d4d4686969691908,0030c0c8cccdede9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.