Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF63FB9938887016476380D3A4BB3B8AF7391C2FB91815D174B4CBE572B88F5616AF4F |
|
CONTENT
ssdeep
|
768:gyWuPyuW5u5L//C8onGQRzLcoN9BzFvXUsz8n+IDS/u11KWU+dFfISZ5CTH+M27V:QHnixzumCyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b10cccc667c6d999 |
|
VISUAL
aHash
|
d3c7cbc7c7c7e7c7 |
|
VISUAL
dHash
|
0696960f1d1c1e1e |
|
VISUAL
wHash
|
c3c3c3c3c7c3c3c2 |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
0696960f1d1c1e1e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 699 techniques to evade detection by security scanners and make reverse engineering more difficult.