Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B864C9F3F1712436139F41CE9126358E74D2E28ADF8149E8E6FD436CAAE1DD1B682748 |
|
CONTENT
ssdeep
|
1536:KR+YPPk2Pe+P/2KjZzuy4XmLGzFCewQLS74WLzFgODNu6Ls7kwESzF20Gago7hmP:KRlJ4CedrEVBd1Ip3hx4LR9BcOXluaX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e963c61e1c92696b |
|
VISUAL
aHash
|
10c3c1c38181ffff |
|
VISUAL
dHash
|
741b9b1f3b330036 |
|
VISUAL
wHash
|
00e3c1c38181ffff |
|
VISUAL
colorHash
|
06001018080 |
|
VISUAL
cropResistant
|
351b9b1f3b330036,325255d594ca6be0,8cd2d22c0cd2d244,3e2c3436edecb4f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 86 techniques to evade detection by security scanners and make reverse engineering more difficult.