Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1942343305904ED2702DBA5C4A172972A62F58345C653068AFBFAC3FA2BDFC68DA37145 |
|
CONTENT
ssdeep
|
384:YiIisiIroUa87x7KNwU+OujR86C97WuCCF1npKDu9hANbzsJO5xVZjqTSbft:vfDfUf7x7K2JR8vWuCLOKzsIx/jzF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2156dc592946d79 |
|
VISUAL
aHash
|
000084feeee40081 |
|
VISUAL
dHash
|
4c020dcccccc020d |
|
VISUAL
wHash
|
e2c0c4fefee4c0c1 |
|
VISUAL
colorHash
|
38000008180 |
|
VISUAL
cropResistant
|
e4c2a06464c4e0e0,4c020dcccccc020d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 65 techniques to evade detection by security scanners and make reverse engineering more difficult.