Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1385341216254AD2E61AF8BEAF5B2B73451F9C34EC1134698F6BD83F4178BC59E633180 |
|
CONTENT
ssdeep
|
1536:RAsIxztO2adNboE+skbdlKG2adNboE+skbdlKU/QsUMw7kEYtleQ0yIw7ZF:WwDrNIw7P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
82d42c7db3963ec1 |
|
VISUAL
aHash
|
1e7c7e6e60000481 |
|
VISUAL
dHash
|
f4e0ccccdc228445 |
|
VISUAL
wHash
|
3e7e7e7e66004483 |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
f4e0ccccdc228445 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 110 techniques to evade detection by security scanners and make reverse engineering more difficult.