Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F54DE234219792A4437C3D034699B7BD1A6DE8BFAA70A404EDCCBF76AFDC50741A21D |
|
CONTENT
ssdeep
|
1536:VWUgQmTa3MZo+Hd1+u3uLd+Smfu4/ZT4oU5y3SUby0itZv5KIwmvSpO5CmBPR+wp:0OQLifQ5/y0iB4Y3p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc1ed164e7939864 |
|
VISUAL
aHash
|
ff819fbf839fffff |
|
VISUAL
dHash
|
c83b345966349e16 |
|
VISUAL
wHash
|
7e000e1e021effe7 |
|
VISUAL
colorHash
|
07030000000 |
|
VISUAL
cropResistant
|
c83b345966349e16,450501b2b2010545 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.