Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T178F122E1C044DC3A535385E5F7F52B5F7696C345CF020A8853F893AA5BDACA0CA23A99 |
|
CONTENT
ssdeep
|
96:TkUuS7kh4lzH0XfeGnV7D8DEVz6UwvFveRXXHF2edXTz//V7DeCQ7R:QUuS7kh4lzH0X1n+DEVx9/hz3ACQ1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
941114143bbe6f6f |
|
VISUAL
aHash
|
007effff00007eff |
|
VISUAL
dHash
|
beb0a20049a4ac51 |
|
VISUAL
wHash
|
007effff000056fc |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
be96aaa230302848,acacaeaec4210000,459ebeb692aab2a2,8453acacacacaeae |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.