Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16F1263A0C854ED63475E86D4B77C6B8F7A92C7C9DA43094893F8839ECAC7C98D61015F |
|
CONTENT
ssdeep
|
96:TkB0SzeFvMSfuSTCctutQbSS8lWowwvF+9eBX/HFIexXgz/3Y7zkn190Y8902h9x:QB0SzeFdjWcktQQWYF5mzvhIqoIMuA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9aa5f91ee7400ae3 |
|
VISUAL
aHash
|
ffff7f7f3c0818fc |
|
VISUAL
dHash
|
a233e9e969f9b9c9 |
|
VISUAL
wHash
|
ffff7f3c00001838 |
|
VISUAL
colorHash
|
06400018000 |
|
VISUAL
cropResistant
|
a233e9e969f9b9c9,6d6171e1f0707079,f9b8e3a6a9c9cdc7,652564cc70310347,5c6c6c2466131319 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.