Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17BE3C8F05508DD92458783E8E636137A31D996C9CB430685A3F88FE9FAF5DF6CC2A940 |
|
CONTENT
ssdeep
|
1536:LsIxDe1piVqP/3xbeee+eeeReeeCeeehvaFfbgIjMIbqCw79F:LipiVqP/3xLCFE7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
81a75c3d399d27c4 |
|
VISUAL
aHash
|
07777f6f4707de59 |
|
VISUAL
dHash
|
3ee4ceda9e7eb0b1 |
|
VISUAL
wHash
|
07777f634702de40 |
|
VISUAL
colorHash
|
08200030000 |
|
VISUAL
cropResistant
|
3ee4ceda9e7eb0b1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 112 techniques to evade detection by security scanners and make reverse engineering more difficult.