Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T150D2F16C301805578B379DCBD0612A5A38AAF34AA715C1C4DBEB76760EFB8267CE4473 |
|
CONTENT
ssdeep
|
192:VElr/LNF4NFTQxLrup7IM8sb8gSkRNB+ewevqMeBVe3+seo1vvbXrleNxsOvTgya:+U7+7AVI4aBUG6JUG6IvwuVi3kfMTUL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e666cc8c99933399 |
|
VISUAL
aHash
|
e3c3c3e7ffe7ffff |
|
VISUAL
dHash
|
45454d4c304d0418 |
|
VISUAL
wHash
|
c0c0c0c0c7c3c3ef |
|
VISUAL
colorHash
|
07000200070 |
|
VISUAL
cropResistant
|
45454d4c304d0418,80d0e0c4ce2639f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 56 techniques to evade detection by security scanners and make reverse engineering more difficult.