Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FED35F31464799BB559392C0A7762F4BA3C09309C6938B0363FED78F4FDAE51EC29642 |
|
CONTENT
ssdeep
|
1536:vkmHrkmHyL4431Cth4Deeeseee1eeePeeeqeeeeeeeJeeeCeeeseeepeeeUGQoQh:vNLNx9twry3z8ZyOTHz/39Kt0ICss |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c44ab93ab466cde2 |
|
VISUAL
aHash
|
000030000000ffff |
|
VISUAL
dHash
|
32f3c4c4cce4c332 |
|
VISUAL
wHash
|
181870766600ffff |
|
VISUAL
colorHash
|
3ac00018000 |
|
VISUAL
cropResistant
|
22c03232423c3ac0,3232c4c4c4cce4c1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 139 techniques to evade detection by security scanners and make reverse engineering more difficult.