Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D333BE93D41B5125F7341D3A0AF354BB33E251FA80D4CA0A164DEE974F84A9602BF9E |
|
CONTENT
ssdeep
|
768:lyWuyWNwPiu+0fQFWSD5R0M9X5QjX8xOq1CENn4d0fSxHyOzxHRBaW/Sy3sIWj8O:qj1CEN4dPyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8d52b352a352bd5 |
|
VISUAL
aHash
|
00fcfcfcfc000001 |
|
VISUAL
dHash
|
3380e0808020aa09 |
|
VISUAL
wHash
|
00fefefefc804a01 |
|
VISUAL
colorHash
|
10003000018 |
|
VISUAL
cropResistant
|
6444d55b5b5237b3,c2a2e02b23ab92c2,3380e0808020aa09 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 473 techniques to evade detection by security scanners and make reverse engineering more difficult.