Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E2843CE063A02ABA419787E4B5317357F29B527AEA27D88CF3DC87556BD7C2DCE10180 |
|
CONTENT
ssdeep
|
3072:ebvw5gxm+MeH7LZtXZeiHPCuuUZs5RwL4ZujVgub5tIZ/rvLfqLLaZtmZeiHPCuT:/gxcet |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d612bd26f642d692 |
|
VISUAL
aHash
|
00001c2c2400ffff |
|
VISUAL
dHash
|
ec30e9c96d647904 |
|
VISUAL
wHash
|
04003c7c3c30ffff |
|
VISUAL
colorHash
|
3200f000040 |
|
VISUAL
cropResistant
|
000000080a001616,ecf679c9c96d6470 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 75 techniques to evade detection by security scanners and make reverse engineering more difficult.