Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18CD132E1C414DD3303538AD4E7F56F0BB391C349CB431D8467F883AA6BDACA0CA55A98 |
|
CONTENT
ssdeep
|
96:TkweTMOpeXOXeFvMSfuSTCctunyt7lHYXSSNBbF4aXvHFaCXCx/SCYfGJ:QweTZY+XeFdjWcknyrHYd0xaA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1cece3331cc4c33 |
|
VISUAL
aHash
|
fffff3c3c7c3ffff |
|
VISUAL
dHash
|
120016169a1a0208 |
|
VISUAL
wHash
|
00ffc3c3c0c0fcfc |
|
VISUAL
colorHash
|
07001400080 |
|
VISUAL
cropResistant
|
120016169a1a0208,26420bd6d4c6ce9e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.