Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19EA28B7490ACDB3B01D3D1E0DA74278A7BF08684D55226A053EDC79C0FFEEA9DE69814 |
|
CONTENT
ssdeep
|
384:c6gRn84EOwwBpktSUNNt6u0iXLEg6jRd9wmno6DJcRqLj0K/:q8wGBBz0mLxIt1ce |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed5f12124d6d471a |
|
VISUAL
aHash
|
008ffbf19fffc3ff |
|
VISUAL
dHash
|
33193332330c9696 |
|
VISUAL
wHash
|
008f91b19fe7c3c3 |
|
VISUAL
colorHash
|
07000000046 |
|
VISUAL
cropResistant
|
33193332314c9696,00100832b2b23008,6665456a4a454963 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 150 techniques to evade detection by security scanners and make reverse engineering more difficult.