Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159323232944B9E1B6947D1CBF670771A21C0C6859B1626C2AEF8572E7BCECE1DC127E0 |
|
CONTENT
ssdeep
|
192:XoyLv3xpKel3FaOn30eiGmnwSmvFnstUx/eks6Q85KKWv6/bUqz/gc7UinNuPcxz:XoqTK8nh3mnXQWu/dA89p/wX4U80Pcxz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e0fe1e01c1fe3e0 |
|
VISUAL
aHash
|
1f1f1f1f1f1f1f1f |
|
VISUAL
dHash
|
74747474f4b4f4f4 |
|
VISUAL
wHash
|
1010101010101010 |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
74747474f4b4f4f4,1b676d1b261b65e5,5a4f7f5b9f5f3f1f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 106 techniques to evade detection by security scanners and make reverse engineering more difficult.