Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10D3350305440D93742DB96D85632AB6A62F98345CB674A88FAF8C3E91FDFC69CE37104 |
|
CONTENT
ssdeep
|
384:+7JngVF0u9bGnb4s0HZs14M14MeV1IxW7zELsRj4j4GMGAraMfsJO5xVZjqTSBrH:LJFz21JVMmrj4TraMfsIx/j+Uf79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9dffc0c2c13c186b |
|
VISUAL
aHash
|
ffff899b8804027f |
|
VISUAL
dHash
|
710633727a68ceca |
|
VISUAL
wHash
|
ffff89898006007f |
|
VISUAL
colorHash
|
07200018040 |
|
VISUAL
cropResistant
|
710633727a68ceca |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 440 techniques to evade detection by security scanners and make reverse engineering more difficult.