Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1129264F2E155A937072780C5F2B1ABAE7BD28248DF031B5413F883EA67CECA195055DE |
|
CONTENT
ssdeep
|
384:PNzM7124AvU7lYYw5Z4ZdZ0ZbCNZ4ZdZ0ZEe+M8F:u712FUJYYw5Z4ZdZ0ZbCNZ4ZdZ0ZEe+v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a37608dc88ff2276 |
|
VISUAL
aHash
|
3fe7e7677fff3f3f |
|
VISUAL
dHash
|
600c4dccc0ccc0d1 |
|
VISUAL
wHash
|
1ec3c3033f3f3f00 |
|
VISUAL
colorHash
|
07000000043 |
|
VISUAL
cropResistant
|
600c4dccc0ccc0d1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 72 techniques to evade detection by security scanners and make reverse engineering more difficult.