Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T189E37673D8413E23115391E9B169F70EB29A436ADE071909C6E18B3A6FC3DD5EF121AC |
|
CONTENT
ssdeep
|
3072:G93kjugm4mMMlGO9ja2INilPdydmtAaZ2FKBmRHVB09tiGpH/RD3Fo9qlp/X/QDi:G93kjugm4mMMlGO9ja2INilPdydmtAav |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c99867e6cc269999 |
|
VISUAL
aHash
|
c38bdbd9d9d90101 |
|
VISUAL
dHash
|
2e33b2b2b2b38f87 |
|
VISUAL
wHash
|
d3cbdbdbd9c10101 |
|
VISUAL
colorHash
|
33011000200 |
|
VISUAL
cropResistant
|
cc9c9a6d1949c4e4,2e33b2b2b2b38f87 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 261 techniques to evade detection by security scanners and make reverse engineering more difficult.