Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T146430BF93D85B5120B7351D361AF364AB33A641F680C59A0B060DEE975F84A9602BF8F |
|
CONTENT
ssdeep
|
768:yyWu/PsyWcNwGH51uSZ/u1v+Lo/LzCWIM9XR/zMQjD8nq3X8UL5UjyQoNSxHyOz6:0UJTyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a76475145c571e53 |
|
VISUAL
aHash
|
00e3e3ffff7fffff |
|
VISUAL
dHash
|
84074bc1f1f0c078 |
|
VISUAL
wHash
|
000040ff7f1f3f1f |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
84870b83f1f0c078,00040494d4940400 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 693 techniques to evade detection by security scanners and make reverse engineering more difficult.