Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1770262E1D0A4DD360B1682D5BBF57B6FB6A2C305CF020D8453F813AA97CBDA1C722599 |
|
CONTENT
ssdeep
|
96:TkUIwazHwLISTRKUEbt7aLwvFg50QeNXSHF7eJXuX/VSTu13GAT43a:QUIwazHwLBYUEbo7CsIIXc61Z8K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bb4a2c2d6142cff1 |
|
VISUAL
aHash
|
090d0d0d0f0f0f4f |
|
VISUAL
dHash
|
1b1959d9195e9f9a |
|
VISUAL
wHash
|
0f0f0d0d8f0f0f4f |
|
VISUAL
colorHash
|
06601000080 |
|
VISUAL
cropResistant
|
0923a765e7d0e1a0,0010096474f08190,4c4cd994949c6060,98cc1c7464c8c978,a6135990b2b3f341,0081421213136380,3d2c6c2f37b766f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.