Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD5364318109AC3B0AE706C997799B69F1E99307C3160D48FBF487AACF5AD2CDA37151 |
|
CONTENT
ssdeep
|
768:yX98byc93dQNa0JysQpVYogZOeN7JdsIx/j+Uf7hpF:VdQNa0J7Q0ogZOeN7LsIxN7LF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e574cc6e291b3a1 |
|
VISUAL
aHash
|
30180f0f3f171f01 |
|
VISUAL
dHash
|
65725a786daebadb |
|
VISUAL
wHash
|
301a0f1f3f1f1f03 |
|
VISUAL
colorHash
|
16010000c00 |
|
VISUAL
cropResistant
|
65725a786daebadb,80c8e3a2eef8c08f,e5e5cad5d0cf8f8d,0ffaa2b69a82bec8,793e3397b9d9ada5,2189cdeda56c6d2d,bb73c6cf4f4b3171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 77 techniques to evade detection by security scanners and make reverse engineering more difficult.