Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3538D307B32747C92EF54EDB33C66066AD2D64EE9C74590B1984A8E23C3CA529177BC |
|
CONTENT
ssdeep
|
1536:aeH17mKjgtwXMCBfwxMCBTYlMCBfVN2/y9dGXDiJZBlvy40hxwfwH:amywhw7YpN2aDSw0Ea |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0cccf3367cf3030 |
|
VISUAL
aHash
|
ffdfcfc7c7c7ffff |
|
VISUAL
dHash
|
48303c1c8d9c3024 |
|
VISUAL
wHash
|
0000c7c7c0c0c0f0 |
|
VISUAL
colorHash
|
07003008000 |
|
VISUAL
cropResistant
|
48303c1c8d9c3024 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 135 techniques to evade detection by security scanners and make reverse engineering more difficult.