Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EBE2A7B0B198D86249C797C0A233176933A6D391DA8311D096F4C7B947ABCE9FE27F14 |
|
CONTENT
ssdeep
|
384:7sdM/MqMZMSUR5744fgLXqugsGVg7iwdL1ODcft:yM/MqMZMSk44wl1hF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ed193cc3b318ecc |
|
VISUAL
aHash
|
7e7e380010305e3d |
|
VISUAL
dHash
|
e8e0e01aa4a4d449 |
|
VISUAL
wHash
|
7e7e3c0010387e3f |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
b87066c8d0900102,e8e0e01aa4a4d449 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 134 techniques to evade detection by security scanners and make reverse engineering more difficult.