Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T165B230309040AA3740D3A2D2A7355B9FB7C2C381CA27070E62F8C76D6FE7C55DD2A666 |
|
CONTENT
ssdeep
|
384:70yGC44Mqlh01qCpezUKXNW2kbPKNyK0W+KFZKpK+SAft:oo449hWqCpezUwWNbP1RVQijSAF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d39a1acb91bcc33 |
|
VISUAL
aHash
|
000000187affffff |
|
VISUAL
dHash
|
3a0671b0b2a25cb2 |
|
VISUAL
wHash
|
000000187effffff |
|
VISUAL
colorHash
|
180000001c0 |
|
VISUAL
cropResistant
|
e280c2adacc280e0,3a0671b0b2a25cb2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.