Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B5319A01190053EA09787D8E731672E73DB909DE76B2110D3F9C7B86EC5EDDECA6188 |
|
CONTENT
ssdeep
|
1536:+YhdLqbR3D+0MXioF7Y/nXPxfEXi226Ph95musmRCmNkbmfdQFU:+MdLqV3pMXioF7YP/xf02ChLmZmMmNku |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc3946c66366391c |
|
VISUAL
aHash
|
60df89c1bfe7b7b3 |
|
VISUAL
dHash
|
cd30338b654c2422 |
|
VISUAL
wHash
|
408389c3b5e5b7b3 |
|
VISUAL
colorHash
|
07000180001 |
|
VISUAL
cropResistant
|
cd30338b654c2422 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 487 techniques to evade detection by security scanners and make reverse engineering more difficult.