Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B693827523441A3E994783E4FB647F39C29E8346D2179C8DB3F982635B82C68EC176E4 |
|
CONTENT
ssdeep
|
768:elHmqkgmPz0OCUB4BgopvlCtLvZxTSPa4Bm4E7dwvZA7D/2T4j8888W/8888zl8g:e2FB4YJ8888W/8888zl8888HpSk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c907364f589df94 |
|
VISUAL
aHash
|
0f0f3f3f13130385 |
|
VISUAL
dHash
|
fed9fbf3b6e7fb6d |
|
VISUAL
wHash
|
0f0f3f3f1f130381 |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
2529b9aece5132d3,fed9fbf3b6e7fb6d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.