Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19DC1BC60C101782B3E87A8D659F1BB1D4DF2C6B9DD0211C8E3792DCE4FCAD64919AAA1 |
|
CONTENT
ssdeep
|
96:QCqAp23K/EeLP5k8w7c+h+hgJoj08pRZgh/7w45vI+hg+mh6Q05YRZ+PUrKMrcCS:Qgw8w7cAPq0M+7w45Qk+n0sXs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e5870349f9bca62 |
|
VISUAL
aHash
|
00003c3c3c3cc3ff |
|
VISUAL
dHash
|
28966961617186a0 |
|
VISUAL
wHash
|
00003c3c3c3cffff |
|
VISUAL
colorHash
|
080000001c0 |
|
VISUAL
cropResistant
|
8e8cf2e4e01373a2,28966961617186a0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 236 techniques to evade detection by security scanners and make reverse engineering more difficult.