Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15E622AFD9204147E85178BACAF1CBEB6634F6885D80511A1CBECCA3955E2EEEF803525 |
|
CONTENT
ssdeep
|
384:8hHo6JjCt2dxNmm2JmgCeFyGfXKz/frGB:6oKjfZjeFyi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3b3198d278e8c8e |
|
VISUAL
aHash
|
afe7ffc3e7ffff00 |
|
VISUAL
dHash
|
5a1c1c0c0c000c0c |
|
VISUAL
wHash
|
0cc3c3c3c3f3ff00 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
5a1c1c0c0c000c0c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.