Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15051F07090748C174283D2D0B9A0EB5B3993839ACB071F2517F48B5FFADED69CD58199 |
|
CONTENT
ssdeep
|
48:w5u6PpQ1yspJIG4d+FVkktcwD9/lZrqkmizFwQjCZFFwdaFythq8tLm4MbNWELiQ:YusSbVViwD9dZmkvzJC9BynF9MoELd5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e19852744c6f53b3 |
|
VISUAL
aHash
|
4eef6f31e3e3e1e1 |
|
VISUAL
dHash
|
949bdbe3474a4b8b |
|
VISUAL
wHash
|
646f2d31e3e3e1c0 |
|
VISUAL
colorHash
|
07203008040 |
|
VISUAL
cropResistant
|
949bdbe3474a4b8b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.