Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T166F104E1C048DC3A131385E6B7B52B5F7596C349CF060E8853F892AA5BDBC60C927A99 |
|
CONTENT
ssdeep
|
96:TkU837khOlzH0XfeGnVirtEBkwvFGeBXIHFqeQeXbz/9ViF07QPJ:QUu7khOlzH0X1n6tEZKL1zlV7QR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c303436db83cfca6 |
|
VISUAL
aHash
|
0000ffffff0000ff |
|
VISUAL
dHash
|
dccde4208a236c03 |
|
VISUAL
wHash
|
0000ffffff0000ff |
|
VISUAL
colorHash
|
03000000007 |
|
VISUAL
cropResistant
|
d9cdcc203830084c,0100000000000000,044420cbdcd1c9cc,2303232321cc6b43 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.