Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BB730B9A2894601A472740E394B72BC9F7391C2FF91956D2A4B4C7E1B3BC8F53169B0F |
|
CONTENT
ssdeep
|
768:ayWuD5uPWC/LyfF8n+v1xz/9XMcGvR1ZTb/uWHjwq1nUyyStRGcs5F65uQFRSHQG:ZtdQLyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e44cd99393ce3233 |
|
VISUAL
aHash
|
ffd3c3c3c7c7e7e7 |
|
VISUAL
dHash
|
021686060f0d0e1c |
|
VISUAL
wHash
|
c3c3c3c3c7c3c3c2 |
|
VISUAL
colorHash
|
07001030000 |
|
VISUAL
cropResistant
|
021686060f0d0e1c,0d4d4c2f0b130b6c,f2f0e2f6eee0eace |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 698 techniques to evade detection by security scanners and make reverse engineering more difficult.