Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E624B77431116A7F45978AA4B0E0671BA26FD30DC82BCD79B3DCC2A72FC6C61CD6A644 |
|
CONTENT
ssdeep
|
3072:obZU7Zde4Dhnj1AVj5TtfZavhu73ewUwPAOM4okQ9Wv56g1gVYb8cci7ILtkyrX1:oar+ouGO+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
84329f76d2727670 |
|
VISUAL
aHash
|
063f1f550e02033f |
|
VISUAL
dHash
|
bcf8b8a9dcecaee8 |
|
VISUAL
wHash
|
043f1f5d1d02173f |
|
VISUAL
colorHash
|
00000600018 |
|
VISUAL
cropResistant
|
bcf8b8a9dcecaee8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.