Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12494B6E080340E7E456742FDF76DFBD4E3EE4199E72700921AFC9B054AA5D60E9AF029 |
|
CONTENT
ssdeep
|
1536:yZB3vkxjMDg3VvDABM1Uic8yUohId9WRkfj3rJ/IiycJfJzCDXdrKrJrt6iwQck1:yZB8xqQckUwkC69QtVEw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a49a7926c61565f |
|
VISUAL
aHash
|
7f3f00001c0cffff |
|
VISUAL
dHash
|
d4e968b3f0dc5d27 |
|
VISUAL
wHash
|
7f1c00001c1cffff |
|
VISUAL
colorHash
|
03000038000 |
|
VISUAL
cropResistant
|
cce968b3f8dc5d27,100c32b2b20c1000,c0f03e0789290086,c03c1f9090949090,0bab0bf1c1f86436 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.