Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T157E2DF206805EE2341DF9AC99672562962F98349C61306C9FEF9C7F90BEFC6DCA33115 |
|
CONTENT
ssdeep
|
384:EHgSPMF4c77Rrzrjo3VhB3MI5SsJO5xVZjqTSmirxroUa872:n9hshB3MrsIx/j+irGUf72 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ebc64a690cd8d36 |
|
VISUAL
aHash
|
7e001c1c043f3c18 |
|
VISUAL
dHash
|
f40d70310dc9f0f0 |
|
VISUAL
wHash
|
ff003c1c0c7f3c3c |
|
VISUAL
colorHash
|
38200038000 |
|
VISUAL
cropResistant
|
f40d70310dc9f0f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 72 techniques to evade detection by security scanners and make reverse engineering more difficult.