Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16BE155D1C054DD37032286D5F7F56B5BB9A2C359CF0209C493F842AB9BDBC70CA16A99 |
|
CONTENT
ssdeep
|
96:Tkltd7moh4lzH0XfeG9Edt7rJwwvF5eFXBHFneRXgz/Ft7rjqQPJ:Qltd7moh4lzH0X19Ed1Je/ouzt1jqQR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b99369c6c66c4656 |
|
VISUAL
aHash
|
80c3c3c3ffffc3c3 |
|
VISUAL
dHash
|
161e1f17000f1717 |
|
VISUAL
wHash
|
00c3c3c3ffc3c3c3 |
|
VISUAL
colorHash
|
070030c0000 |
|
VISUAL
cropResistant
|
161e1f17000f1717,a424c9d9915b24a4,495656acecd458c8,692d2c0c86b6b430,e29090a894808001 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.