Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11854B4DD5B761AECF584A3EAAB1254783947CDE26C12C864C3EC4D3A7985C9C9C21C8F |
|
CONTENT
ssdeep
|
1536:WGkqhyFtkqhyFwyeMUi3xfDJC9d7SQDyOZqhyFBHbwF3i2nrwqhyFBSYdqbx3ZSV:WOWMUi35l7P8o1IB4zAkgSjKz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
932bce2c29926f8e |
|
VISUAL
aHash
|
87002c0c00007e7e |
|
VISUAL
dHash
|
572c485829d4fcd8 |
|
VISUAL
wHash
|
ff002c2e043c7e7e |
|
VISUAL
colorHash
|
30006000000 |
|
VISUAL
cropResistant
|
572c485829d4fcd8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 98 techniques to evade detection by security scanners and make reverse engineering more difficult.