Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19FE143E1C054DD27032385D6F7F56B5F6692C349CB020A8463FC82EB5BDBC60CA567A9 |
|
CONTENT
ssdeep
|
96:TkwB7khOhHWfeG9VKDbSS8ct76kWSSIwvlde9X9HltetXmz/vQPJ:QwB7khOhHW19g54kBHCYz3QR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b69ad87c232a387 |
|
VISUAL
aHash
|
7f00003c3c3c00ff |
|
VISUAL
dHash
|
cf3333f160683648 |
|
VISUAL
wHash
|
ff19003c3c3c02ff |
|
VISUAL
colorHash
|
06007000080 |
|
VISUAL
cropResistant
|
a480809b4927a636,cb8a1a8a9c3d3b33,c2a0b2aab2aa8cae,3481200000000000,cf333313f1686836 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.