Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7F2837031411AB721D383F6A3E6A72EB1F6C769C227CE48B7F9429957D6CA4CD02714 |
|
CONTENT
ssdeep
|
384:HA2JYMESW3Gm8VN2twUdeyFYhgchSsi5ooXVFoeIzxy9Prqk+gKKDPSZl2H+zoxz:7JO34y+dSsX2FxP3R5WZUes+cR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edc692b943ec2cc2 |
|
VISUAL
aHash
|
ffffd1f1f191fbfd |
|
VISUAL
dHash
|
512c2723033333cd |
|
VISUAL
wHash
|
fdff9191c181f900 |
|
VISUAL
colorHash
|
06000e00000 |
|
VISUAL
cropResistant
|
532c2723433333cd,4f4d4bcb8f938b8f,3533d4d494d43335,0000000000030303 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.