Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FBA35933421975270537C2D520B95B77E2969E4FFAA70A010FECD7FB2BEAC90B45A109 |
|
CONTENT
ssdeep
|
768:/aHRzfxZ/DFTksPhwfjTOIhIEBa4QjViTqetGKmf9RazU3V0d:aZRTksPSGIhIEBa4Qjo+7KmGIV0d |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96e6e93c34c3c361 |
|
VISUAL
aHash
|
062676660438187e |
|
VISUAL
dHash
|
cceccccc0c7131d4 |
|
VISUAL
wHash
|
66767606043c187e |
|
VISUAL
colorHash
|
31000c00200 |
|
VISUAL
cropResistant
|
8400a51d8c313280,cceccccc0c7131d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 161 techniques to evade detection by security scanners and make reverse engineering more difficult.