Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A8D1102064A99D37910B86D5A3E9DF4A75C24388EE072A08B7F8935D2BFFCC4DD09C25 |
|
CONTENT
ssdeep
|
96:7b4VyMqGg9E7QBjI/n8S+eh3hsi2n5FPAtLrrZiHJyV8A+TKSl7TT:7biX+ju8S+eh3x6gbVgTKSl7TT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
999966669933cc99 |
|
VISUAL
aHash
|
0018181818180000 |
|
VISUAL
dHash
|
0c32b2b2b2b2320c |
|
VISUAL
wHash
|
38383c3c3c3c3838 |
|
VISUAL
colorHash
|
00000000007 |
|
VISUAL
cropResistant
|
a2c06e0f135f808a,8e8ed6cecc961733,0c32b2b2b2b2320c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 185 techniques to evade detection by security scanners and make reverse engineering more difficult.