Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F5936430A640D93B409782C5A6325B2A62F6C346CA13499CBBF183FDDBDED68CD37165 |
|
CONTENT
ssdeep
|
1536:PN7sIxrSkTv0xoiaeMXpmeX7hmwzThuYyCxxdMtSWxoaek79sjkm:PN7QMXpmerEcXJ7dqoaek7lm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
926ae913e564da65 |
|
VISUAL
aHash
|
40000426060c02ff |
|
VISUAL
dHash
|
90c0cdccccc88ed6 |
|
VISUAL
wHash
|
7860047e6e2e42ff |
|
VISUAL
colorHash
|
11006200040 |
|
VISUAL
cropResistant
|
7ef28a37243038c2,f1f3923499d1c2e4,c100a2a2a2828080,90d04dccccd8a886 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 76 techniques to evade detection by security scanners and make reverse engineering more difficult.