Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17A3272705258AD3E416381D9E37A272F30DA929EDF8F030097ED63F91AD7C59EC26055 |
|
CONTENT
ssdeep
|
192:MXEHxTEOsT1uofsh3l9TSgu0TlchwTPKYDDcTHW9IIUA3/TzvyhiNQC:MXEtEOO1uofsh3/SguElchYPzDc29IIv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cdc3333cccc9933 |
|
VISUAL
aHash
|
1800181818180001 |
|
VISUAL
dHash
|
3038b2b2b2320f13 |
|
VISUAL
wHash
|
3c3c181818190303 |
|
VISUAL
colorHash
|
38000002080 |
|
VISUAL
cropResistant
|
f3d1a68cb9e8c00d,3038b2b2b2320f13 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 142 techniques to evade detection by security scanners and make reverse engineering more difficult.