Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11C235A726332B8B843DB91DEF7382E46B2D29489F9C74550F5C8968D23C3C816597BB4 |
|
CONTENT
ssdeep
|
768:at+EsZx8/G8LhRF4rDaw6MLBeowyMLBekwZUcix+y9dQpUDF1E56ITmHDLBABW8n:at+EsZ/8LDOrDaw6MLBTwyMLB1wZUXx8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fb6b853e84c56381 |
|
VISUAL
aHash
|
818181818181ffff |
|
VISUAL
dHash
|
030149557501170f |
|
VISUAL
wHash
|
f38181818181ffff |
|
VISUAL
colorHash
|
33200030000 |
|
VISUAL
cropResistant
|
030149557501170f,0300d898a4e41833 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.