Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13131DAB621141716164B7BD15591B3FFB48B8B8ED5055D9879FF42D9C3E0CEA4C90120 |
|
CONTENT
ssdeep
|
24:hR/C7YKHoUN/+TN/0AJniZctaY5abuogWC2lO2u2BzMoMli8PXIhSAEzJS2DeZmQ:TmIUNmTNMYscz4uOCYOLWzM/c8fS2N6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99669b6699cc8e26 |
|
VISUAL
aHash
|
0000181818001818 |
|
VISUAL
dHash
|
00081030100c30b2 |
|
VISUAL
wHash
|
30301c1c3c3c3c3c |
|
VISUAL
colorHash
|
38001000180 |
|
VISUAL
cropResistant
|
00081030100c30b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 172 techniques to evade detection by security scanners and make reverse engineering more difficult.