Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14C933AF0E540FD2316F34093709A9647F3BA191BF91949A0B64CCBCAB3EAC3711676A5 |
|
CONTENT
ssdeep
|
768:2GT0TQH7YFUxc5QwV8ZHDelC9gQW+RxTZqoc6OnW0zT+lfL4fUwijz6Vzc+b42NM:2RipD4PQW+RxTZNcxAwrzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c393dd65bc64b031 |
|
VISUAL
aHash
|
7e7c7c00000000ff |
|
VISUAL
dHash
|
d4f0d8ccc8e1e05d |
|
VISUAL
wHash
|
7e7e7c00383030ff |
|
VISUAL
colorHash
|
38000098000 |
|
VISUAL
cropResistant
|
e0f1b99c9c392daf,35c5353535852505,d4f0d8ccc8e1e055 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.