Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13E334A726332B8B843DFA1DDF7382A46B2C3998AF9C74694B1C55A8D13C3C8161977B4 |
|
CONTENT
ssdeep
|
1536:aN+EsZ/8NLDOgDawYkM5BaMwY/M5BaSN2/y9dGoDF1sPnTA4IE3wtwH:aCFLwawZN2aD3Hsqa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eec1e4c491f1ccf0 |
|
VISUAL
aHash
|
f181818181998181 |
|
VISUAL
dHash
|
4771337171714d31 |
|
VISUAL
wHash
|
ff99899999999181 |
|
VISUAL
colorHash
|
39003000180 |
|
VISUAL
cropResistant
|
4771337171714d31,82826a7272628aa4,477030f071f08c30 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.