Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1291286E1D494DF36075281E5A7BAB76B36F2C248CB41094453F853BD2BCACB0CE21999 |
|
CONTENT
ssdeep
|
96:TkO10z8inzSJOMbStqRjJTdt7zw/wvF8eRXwHFMeiqX+dX/1r+AT431:QO10z8inyV5JTdxwIaN0XL8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ada5789256d27c83 |
|
VISUAL
aHash
|
ff03032707ffff00 |
|
VISUAL
dHash
|
9f8fa7efefbf0028 |
|
VISUAL
wHash
|
ff03030303ffff00 |
|
VISUAL
colorHash
|
06007000080 |
|
VISUAL
cropResistant
|
9f8fa7efefff0040,b0a86d555571eaf2,6a9594b294858a60,0000002020202020 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.