Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16D322332944B9E1B784791CBF6707B5A21C0C586971626C69EF8572E7BCECE1DC123E0 |
|
CONTENT
ssdeep
|
192:Xoy2v3xpKel3FaOn30eiGmRSrSVvtstcx/kkNQ1+5DeKyu56IIUo/gZV7MDnFuP1:XotTK8nh3mJNGm/Xa1Slyu0qfDMT8P1v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8606f03f1f030f3f |
|
VISUAL
aHash
|
1f1f1f1f1f3fffff |
|
VISUAL
dHash
|
e8e8e8e868e880e0 |
|
VISUAL
wHash
|
101010101f007e7e |
|
VISUAL
colorHash
|
07c02000000 |
|
VISUAL
cropResistant
|
e8e8e8e868e880e0,c777efef2f3703c1,73493c0618337f7f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 74 techniques to evade detection by security scanners and make reverse engineering more difficult.