Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A34F9EEA320D5BE5087C3DCE6119C50769BF2AFEA81C350D05DC7A959A2CADAC0F750 |
|
CONTENT
ssdeep
|
3072:fy7u/b0PiNumWN39STRnwAhwWmwS/w1/w4vwcIwHRnwAhwWmwS/w1/w4vwcIwHRa:fy7u/b0PiNumWN7n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95b55863cb3885c7 |
|
VISUAL
aHash
|
0007370727260018 |
|
VISUAL
dHash
|
96e6e60e4e4c30b2 |
|
VISUAL
wHash
|
07073f3f7f06181c |
|
VISUAL
colorHash
|
300010001c0 |
|
VISUAL
cropResistant
|
d9f8f8e8e26cccc8,a080c0af97b680a4,96e6e60e4e4c30b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 674 techniques to evade detection by security scanners and make reverse engineering more difficult.