Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15EA295A3006B29BE2777C3CE8A10262AE187437ED660D7E4E6D5C7C97293D60F5B2354 |
|
CONTENT
ssdeep
|
384:8LQUJjzH05C0KGOxBSb1tClsFP6viqPNxk:IN3n1BMAlskvJxk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8cd32cd32cd30cd |
|
VISUAL
aHash
|
dfcfcbffcf879f87 |
|
VISUAL
dHash
|
323a1a1a2c3c3a0d |
|
VISUAL
wHash
|
df838b8b87870707 |
|
VISUAL
colorHash
|
072010080c0 |
|
VISUAL
cropResistant
|
323a1a1a2c3c3a0d,2302062600c0030b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 951 techniques to evade detection by security scanners and make reverse engineering more difficult.