Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F6393F0519266770343E3D0E7362B1A72EAA0A5CE56467AD3F8879DAFC5C58DC0FA01 |
|
CONTENT
ssdeep
|
1536:7443OegB8qZNeeejeeeEeeeKeee509uTNn5A6b:NqrA6b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
83835c3d3a5a95ea |
|
VISUAL
aHash
|
187e7f6d4f020000 |
|
VISUAL
dHash
|
f2c4c9d9dbb6314d |
|
VISUAL
wHash
|
3c7e7f7f4f021004 |
|
VISUAL
colorHash
|
38000e00000 |
|
VISUAL
cropResistant
|
cbcbc726414bc0c3,60dc94a2dcf47898,f2c4c9d9dbb6314d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 379 techniques to evade detection by security scanners and make reverse engineering more difficult.