Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T192629360515C997F816383D1A3F6472B32F9C281ED074B0693FCC36A6BDEE80ED52A94 |
|
CONTENT
ssdeep
|
384:1oQC3i7K7I+hmo2O+YSgdpyMA6pu5A1nnqzfhvq5pChyznNBZUr4IRFSbYF2LiF9:1/C3i7c5wBOHSgdplA6U5A1nqzfpq+ht |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b833c74dc3383563 |
|
VISUAL
aHash
|
f9cf878d898b8fff |
|
VISUAL
dHash
|
4b3a1c3b3b3234c8 |
|
VISUAL
wHash
|
008f878d818b8fff |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
6b3c1d3b1b3234c8,001285a5a512a500,c47cc526b0479ede,89d9f79b8b161819 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 57 techniques to evade detection by security scanners and make reverse engineering more difficult.