Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T181526360466DAD37901783E87B6AAF2733A88388DB86020852FCC77E5FD7C45EC66574 |
|
CONTENT
ssdeep
|
192:Ly/51ih/Ikub52gQ4bJITudxkxmkqerf6+3f79zCSfxZ1yzW1qvXRgB2xGR:Ly/fa3ubUJgJIydxkxOwCEf79zJRyzWZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0d57f6a9db28039 |
|
VISUAL
aHash
|
0000ffff00000000 |
|
VISUAL
dHash
|
51848480c2c94d10 |
|
VISUAL
wHash
|
00ffffffff000000 |
|
VISUAL
colorHash
|
0a0060000c0 |
|
VISUAL
cropResistant
|
84808088888088c8,51848480c2c94d10 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 188 techniques to evade detection by security scanners and make reverse engineering more difficult.