Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B534D5E62358A39C8A87D28DAB71E5E8931F90ACF677D6C08A9E837415C7CC4F717940 |
|
CONTENT
ssdeep
|
1536:Dhx7L4a7RZN2NXZedpTaZlbaf7cVfgJhF+nGo1bOTRwJ2oUCie4tjoAfkTQ2WXT1:DpN+QYpkEJfmhoAfMQdQm4Qu65XyJkpf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d88ff0a527708fe0 |
|
VISUAL
aHash
|
ffff3c000018c0fc |
|
VISUAL
dHash
|
163371a868319089 |
|
VISUAL
wHash
|
ffff3c080038c0fc |
|
VISUAL
colorHash
|
38000000038 |
|
VISUAL
cropResistant
|
163371a868319089 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.