Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AC333945F3B35421E57B88DA8C6A1B63629EFA98E016CDD497ED43380EDDC60F50AC0E |
|
CONTENT
ssdeep
|
384:DDC2caZNKbO6JK+mrNXu8ztPu3zC+2QvDUBqD7jhseaF35cxF2M8nHjri+wba9oW:i2LDUF2M6jri+/9ohxo3hxDZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
81736c9bcc99cc33 |
|
VISUAL
aHash
|
1820297d2f3f7f73 |
|
VISUAL
dHash
|
f0cedbd3dbdbdae7 |
|
VISUAL
wHash
|
082028693f3f6f77 |
|
VISUAL
colorHash
|
07201008080 |
|
VISUAL
cropResistant
|
f0cedbd3dbdbdae7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26 techniques to evade detection by security scanners and make reverse engineering more difficult.