Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14EE154E1C054DD37072286D6F7F52B5FB6D2C349CF06098493F842AB9BDAC60CB16699 |
|
CONTENT
ssdeep
|
96:Tk5JJeHkhOhHW0eGUEdt70Ptfo4wvlBetXhHlQeFXN4/Dnt70JOqQ1R:Q5JAHkhOhHWsUEdyllDR34rykqQn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3b341e74c8c4cce |
|
VISUAL
aHash
|
ffe7e7cfe7e7e700 |
|
VISUAL
dHash
|
104c0c28080e0c30 |
|
VISUAL
wHash
|
3f07878fe4c0e700 |
|
VISUAL
colorHash
|
07001008180 |
|
VISUAL
cropResistant
|
104c0c28080e0c30 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.