Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B79486224405EA3B2121CBD45731B749B68BE065CD62414993B183CFEEEFEE69C267DC |
|
CONTENT
ssdeep
|
3072:vXzRWEaCJVX1iqJfrQrHaerSrNaMrvrOaxrjrqalrbrCaNr+rBa12mKb:vXjVXDXs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91b94f51e46e1387 |
|
VISUAL
aHash
|
000f0fc76f0e003c |
|
VISUAL
dHash
|
d5561d9e9edae4c4 |
|
VISUAL
wHash
|
208f0fdf6f0f203c |
|
VISUAL
colorHash
|
19400008001 |
|
VISUAL
cropResistant
|
c17058262cb3ec93,f1e96262f6f49c98,a5a4680cd3d33535,67cc8ca82deded6e,32f2f362e2c8b296,b2e4c4864c133103,d5561d9e9edae4c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 297 techniques to evade detection by security scanners and make reverse engineering more difficult.