Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11A04537021401F7EC2E766F45574DB26F1B9A388EF5F8E56F6F883872B8AC06CA42511 |
|
CONTENT
ssdeep
|
768:iOdFfJqwj6X4LuNrGDaz06ZpsCxm3V5IxkJad3kRxZZrXfRJo54OHz2cd/mwVvhL:zfkwj6Gm2PzFvK1v3PbEWbao |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aad596e0cda1e1b2 |
|
VISUAL
aHash
|
ff1c011919410101 |
|
VISUAL
dHash
|
e9e9cbebb19b9f7b |
|
VISUAL
wHash
|
ff3f0f7b19490101 |
|
VISUAL
colorHash
|
16c00000000 |
|
VISUAL
cropResistant
|
e9e9cbebb19b9f7b,e9e9cba3d99b9f79 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.