Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3A31AF0A290A1F60243CBD4D6317ABAF6A255A7DB034A04C6F18F59DED6CD9CC0D5B8 |
|
CONTENT
ssdeep
|
1536:abKZdlKEOdaYTTmDDAxGq/YYcA8NXpx/G/S0/bbvTaou:abKIYQb6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f470b96994c47bb0 |
|
VISUAL
aHash
|
c08080200000ffff |
|
VISUAL
dHash
|
9200046404010078 |
|
VISUAL
wHash
|
f8e0c0f08080ffff |
|
VISUAL
colorHash
|
09001000180 |
|
VISUAL
cropResistant
|
fcfcf8f8f8f8f8f8,9200002c64040100,68e96849727248f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 372 techniques to evade detection by security scanners and make reverse engineering more difficult.