Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15E2375B352478A3B9993C2C6EB693F6A70DA534FC6450C08BBE94357EF46E64FC06910 |
|
CONTENT
ssdeep
|
768:ZecyfVWPsIZsCFuzsIZsCFuao+aanYh9r2a3uuPgnSnYh9r2a3uuPgnuwQbMo0Yr:ZecuVQsIZsCFuzsIZsCFuao4nYh9r2aU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3c0fe347f113e84 |
|
VISUAL
aHash
|
c67c7c6c60002c81 |
|
VISUAL
dHash
|
1cc0c8d8c478dc71 |
|
VISUAL
wHash
|
c6fe7e6e60243c81 |
|
VISUAL
colorHash
|
38007200040 |
|
VISUAL
cropResistant
|
1cc0c8d8c478dc71 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 135 techniques to evade detection by security scanners and make reverse engineering more difficult.