Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F5B123E0C414ED37435286D5EBFA6B0B76D1C349CB02194097FC83BB57CAC60CA25AAD |
|
CONTENT
ssdeep
|
96:Tk5cjzeNQeSTgG+0k3r1Fw+XZHFmmX9fX/bVYoJ:Q5cjzewkG+d/bXRd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
902a2a9c5ed575b5 |
|
VISUAL
aHash
|
000066ffffffff00 |
|
VISUAL
dHash
|
b1998e80b2b290b2 |
|
VISUAL
wHash
|
000066fffefe7e00 |
|
VISUAL
colorHash
|
07006010000 |
|
VISUAL
cropResistant
|
b1998e84b2b2cab2,0256b2b3b7c89200,b1998e80b2b290b2,793331361f0f2364 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.