Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D4433EB051470AAFDA57E1C9FA645F4AE1C6C20BC7520E49B7F6831B9FC2D60EC89760 |
|
CONTENT
ssdeep
|
1536:/IIIZDdx85B+eeecnJeeecw+eeecnJeeecV+eeecnJeeecH2kF:U8C+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b847f8c62186f707 |
|
VISUAL
aHash
|
0000000301ffdfdf |
|
VISUAL
dHash
|
af014cebbb253516 |
|
VISUAL
wHash
|
0100040f0bffffdf |
|
VISUAL
colorHash
|
12007200000 |
|
VISUAL
cropResistant
|
42a5b53534951612,ef8f494c4ddaebb3,b49a0d4c46434543,170f0f17170f0f07 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 142 techniques to evade detection by security scanners and make reverse engineering more difficult.