Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D8B366193848D2BB1A2B2FC0B9F169E5F5D1B7EEC4A4C464E0FA46C611E1DD286D8C36 |
|
CONTENT
ssdeep
|
1536:cNY7DhR2WVa8NJCtQohYrN+B3UBO03m2D2BOvue7e587y6vCVJYnFePE5lYw5ADW:r7NRznNJqe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e49b4366391b1b66 |
|
VISUAL
aHash
|
e9ff9f9fd3d3d3d7 |
|
VISUAL
dHash
|
2bd4303305252507 |
|
VISUAL
wHash
|
8100bf9fc3c3c7c3 |
|
VISUAL
colorHash
|
07209000200 |
|
VISUAL
cropResistant
|
2bd4303305252507,082c942862e36466 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1530 techniques to evade detection by security scanners and make reverse engineering more difficult.