Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F1A3BD23411975274437C2C134AA5B3BD1A6999FFAE70D010EECCBFA6BFACA0741B519 |
|
CONTENT
ssdeep
|
768:0HgVtpR4nXF6YjOpSpFlTC6rr7LMbvDou2Og0EkfXEvaApGAF:0QtpR4nXBKpSpFl26vHMH0pkv9AF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0613f3b81e0e6f9 |
|
VISUAL
aHash
|
0000f0717804783c |
|
VISUAL
dHash
|
d8d0e7c3d1ada1e8 |
|
VISUAL
wHash
|
0060f1f17874fc3f |
|
VISUAL
colorHash
|
3a000038000 |
|
VISUAL
cropResistant
|
5b49b1352d29ad98,d8d0e7c3d1ada1e8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 115 techniques to evade detection by security scanners and make reverse engineering more difficult.