Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4A36A33411935274437C6D530A55B3BE2E6994FFAA70A010EECDBEB1BFACA0745B11A |
|
CONTENT
ssdeep
|
1536:B8t3vLz4NP/y9svbliCd0EVFFtiuCa28y2O9:YmA7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b813c78ce3679c68 |
|
VISUAL
aHash
|
ff1e8e878f9f93ff |
|
VISUAL
dHash
|
e2b03c1e3c3437c2 |
|
VISUAL
wHash
|
3f0e04828f8f91fe |
|
VISUAL
colorHash
|
07000e00010 |
|
VISUAL
cropResistant
|
e2b03c1e3c3437c2,a0dac7e6c6d7de26,8e9af236264242e5,a8a6e6cdc79693cb,d29ae6eb6276d4d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.