Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156022931A142CC2A05B3D2EAF2B2BF1A61F3E307E701594286E4C39E1ED7D78FA12155 |
|
CONTENT
ssdeep
|
192:vN6Zu8X62sN9lr9llJsidGGEhVtzlXHJdKrajW:UU88PJsiHETtxXHJwrajW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9cbf41e14169635d |
|
VISUAL
aHash
|
00ffffffffff0000 |
|
VISUAL
dHash
|
d0202820500032d0 |
|
VISUAL
wHash
|
008f8f9fffff0000 |
|
VISUAL
colorHash
|
0f0000001c0 |
|
VISUAL
cropResistant
|
2020682020000000,20d0d0d0d0d0d0d0,1010b232ecd4c412 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.