Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10EB374E1BB826436219F52CBE31B170C62C1E3CDCE9156D4A1F48369D2F7DE4BAE0658 |
|
CONTENT
ssdeep
|
3072:ItT31qns/n8hzHVqAOEndDCoFgsZjfLxK32LPADTPQFN:ItT3ons/n8hzHVqAFdDCoFVjfLxK2LzN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b543b8b81ce1c967 |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
2bcdccdccc94142e |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
1b006200008 |
|
VISUAL
cropResistant
|
22282323233320cd,201896262a0e1cb4,1df8c6ccdcc4cc3c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.