Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T178E3DD31588AE937932B8CC6B8A1632E6972C31FDE038BC563BC07DD57D9C64DD22916 |
|
CONTENT
ssdeep
|
384:90ltoMmY4q4TaqzZq9Qv3iLM5sTN6Jk5DbA+TU4d26+bu4CHjoBwpsD3CHqBdLEu:9mto1q9QH+b4C1gGVZz+xgotZGfuyw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91eaeabbc2c292b8 |
|
VISUAL
aHash
|
ff00607e0e0e1000 |
|
VISUAL
dHash
|
111ac8c89838f3d4 |
|
VISUAL
wHash
|
ff087e7e0e0e1858 |
|
VISUAL
colorHash
|
30000600c00 |
|
VISUAL
cropResistant
|
0402897131514903,511ac8c89838f3d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.