Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156E31E717A725632108F32DF932B135C62C3D7CAC7612BF921B8926CAB75E453E93684 |
|
CONTENT
ssdeep
|
768:XgjYxEhStJ5hDfHq15kdPJdDa+M6Jq2WTPm4ZoR/FmBS7ugDZcVFAqc:XgjYx/5hDfHqgdB5a+BGQMeugdcVFAqc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd45323dd99b6644 |
|
VISUAL
aHash
|
0000003838e7ffff |
|
VISUAL
dHash
|
92e2c6f2b2062913 |
|
VISUAL
wHash
|
0000203c38ffffff |
|
VISUAL
colorHash
|
330010001c0 |
|
VISUAL
cropResistant
|
8480807555808088,92e2c6f2b2062913 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 675 techniques to evade detection by security scanners and make reverse engineering more difficult.