Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T163D163B14514983F121BA0C0FAAA2B697491D38FD6024DA073F8837D97DBEF18D6613E |
|
CONTENT
ssdeep
|
96:Z0Y9k9P9u7mO0pOS91HyOCa9rMZJeJ5UW9GzizTAC9rJ8JOaUfQHf9PxvaO+W955:1ytbr36EG345JCI/l8JluQ/CWPGVO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
988d367347ce4173 |
|
VISUAL
aHash
|
031f1f3f0f0f0f1f |
|
VISUAL
dHash
|
77f7f3f3d39fb7b7 |
|
VISUAL
wHash
|
031f1f1f0f0f0f07 |
|
VISUAL
colorHash
|
00007000080 |
|
VISUAL
cropResistant
|
77f7f3f3d39fb7b7,0826fcececc82380,a6478b060c1c1a36 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 379 techniques to evade detection by security scanners and make reverse engineering more difficult.