Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16CD21E31A944EC2740CF9AC85A72566A62F98305C62316C8FEB5C3F95BEFD6CCA37114 |
|
CONTENT
ssdeep
|
384:CrI6sJO5xVZjqTSa6CMad2IE8XHbu/11Ho8GJ5IWrgroUa879ft:C7sIx/jdSxERVYTrnUf79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c34b21cccccef63 |
|
VISUAL
aHash
|
04043038183c3c3c |
|
VISUAL
dHash
|
c4ccc0f0f0f0e8e9 |
|
VISUAL
wHash
|
060638387c3c7e7f |
|
VISUAL
colorHash
|
380020001c0 |
|
VISUAL
cropResistant
|
30f0e082f4e4eccc,c4ccc0f0f0f0e8e9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 68 techniques to evade detection by security scanners and make reverse engineering more difficult.