Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E653FBAA24557016477340E384BB2BC9B33D5C2FE91C45D1A5B8CBF572A88B53127F8B |
|
CONTENT
ssdeep
|
1536:XFusyRijMemQO3naOMQk4MehB8KLMqQSpvDyOloQzZs8oWQbp:k9ds8oWA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f2c656c65613d3c |
|
VISUAL
aHash
|
033f1f3f1f1fffff |
|
VISUAL
dHash
|
967676d6666e4a4a |
|
VISUAL
wHash
|
033f0f3f0307272f |
|
VISUAL
colorHash
|
07038000200 |
|
VISUAL
cropResistant
|
967676d6666e4a4a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 698 techniques to evade detection by security scanners and make reverse engineering more difficult.