Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156F1DDB06199EE3B42C7C2E56375672F32D28386CA9B031093FC939D5FEAC92EC16455 |
|
CONTENT
ssdeep
|
192:SgQkgMYo8kx+Vi3OLZrUMplUM8bUMBqD0wzmvso:skgFjvVi3qUMbUMGUMrwzmvP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3719e1c2c9ec361 |
|
VISUAL
aHash
|
1c2c6c00003c3c3c |
|
VISUAL
dHash
|
2849c9c8d64d45d8 |
|
VISUAL
wHash
|
3c6e6c60603c3c7f |
|
VISUAL
colorHash
|
38200038000 |
|
VISUAL
cropResistant
|
2849c9c8d64d45d8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 79 techniques to evade detection by security scanners and make reverse engineering more difficult.