Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10AA2D772A1402A3F11A7C3C9B362B72DA1DBD188CB89190593FC479E8BD7E51EC1356B |
|
CONTENT
ssdeep
|
384:4Oy5Nko9iVrn8DN620H4jIIII25v/II8QNYMoKfjgjqUjqH6tXfN3S3QK9xvIYsE:4Oy5Nko924jIIIIYwI8QNYM/rQq0g6t2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c345bd3ac54c92c7 |
|
VISUAL
aHash
|
000030300000ffff |
|
VISUAL
dHash
|
9c48c4c2c9cdc300 |
|
VISUAL
wHash
|
00e07c703105ffff |
|
VISUAL
colorHash
|
39000200030 |
|
VISUAL
cropResistant
|
0280800070908000,9c52ccc4c3c9cdc7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.