Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T155F1FBE1D144ED3B475382D5E7B96B4BB791C349CF070A4093F882ABABDAC60CB12599 |
|
CONTENT
ssdeep
|
96:TkKnbzD71tkz3t8v67McddtnlBwvFOe5XKHF2e9XTXX/x1ytE6btmEqzR:QKnbzD71U3t8iIGdtlk8vpXXy6kAEq9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c93926c65656c |
|
VISUAL
aHash
|
fffff3f3d3f3ffff |
|
VISUAL
dHash
|
06182626a6061806 |
|
VISUAL
wHash
|
270f03031020243c |
|
VISUAL
colorHash
|
070400c2000 |
|
VISUAL
cropResistant
|
06182626a6061806,7962e6c6e2e0e0e5,6061e1d8d8b4f8bc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.