Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18341A4A190117CAB02334DFAE3EDEB01F6C2C54AC5862C0162FE83EE16E8D409557E61 |
|
CONTENT
ssdeep
|
24:hRl8C7FWvZiBERpDtLcAovLufs1wrQVgyBQ1wayU5PtmoyBqmMCYYNENsyyDuqwg:T5F2iB8lJcByfY7gF1waJjmoykBCrab2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2724c4c7a7b5958 |
|
VISUAL
aHash
|
00ffe7e7e7ffffff |
|
VISUAL
dHash
|
0d084c4d0c000800 |
|
VISUAL
wHash
|
00e0e0e0e4fcf0f0 |
|
VISUAL
colorHash
|
07006000200 |
|
VISUAL
cropResistant
|
0c0c0c4d0c000000,0045054545458501 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.