Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12C1497F2A114643B42C3E6D052BC7F56E7F19509DAC031C693FCC3AEA69AED499F2211 |
|
CONTENT
ssdeep
|
1536:HcKGv5/4aapQCUhXC8OResjhiHN4Tw2gnp4UY7s33af5z663xPWA2r5Z:G6aapQ/GW3af5z6L9Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d76db892e1a99682 |
|
VISUAL
aHash
|
ff00000000feffff |
|
VISUAL
dHash
|
3725434348781a11 |
|
VISUAL
wHash
|
ff00000020feffff |
|
VISUAL
colorHash
|
060060000c0 |
|
VISUAL
cropResistant
|
0000436067830014,43430b4c781a1803,14676343430b4c58 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 228 techniques to evade detection by security scanners and make reverse engineering more difficult.