Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T131636320B900D93701DB55C4A632975B62EA9384CB131A88FAF487EE5BDFD6CCE37164 |
|
CONTENT
ssdeep
|
1536:1uLsIxR7HFHyGH9sHrO5h1iDkCYTmTUe39RlGvQle9hLMhMjMqdlt79F:1kVlZCpawit7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
872eb951734b1c27 |
|
VISUAL
aHash
|
ffff1830203cfeff |
|
VISUAL
dHash
|
4bf4e1e9e8f0d83e |
|
VISUAL
wHash
|
00ff1820303cfeff |
|
VISUAL
colorHash
|
09400030000 |
|
VISUAL
cropResistant
|
4bf5e1e8e8f0da36,d4d4222c2b2b2b2b,f9fdfdf7f3f6b6de,58834120282091e4,96870d0dcc673333,ec6930184cc67171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 72 techniques to evade detection by security scanners and make reverse engineering more difficult.