Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF0252661162366F13634AF4B2A1B71DE2F9D71EC623CA1C72FC52512BEACC0CA96350 |
|
CONTENT
ssdeep
|
96:TGnNb+b3e/r3WJQGqxyK9xm+NK9x3+sYGK9xk+zFOz0ViHdeDWeUDezhhGrYcVbf:anlweuQZywNNwOewDzxdTpO34g |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b34c4c33591b5b4e |
|
VISUAL
aHash
|
00e7e7e7e7e7e7ff |
|
VISUAL
dHash
|
100c0c5c0c4c0c4c |
|
VISUAL
wHash
|
00c3e7c3c3c3e723 |
|
VISUAL
colorHash
|
070001c0000 |
|
VISUAL
cropResistant
|
100c0c5c0c4c0c4c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.