Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BCD3B570A140A1BF0A3349C560337F6E72D7C35DDA060950A7BCD7879BD7C91EA1AAAC |
|
CONTENT
ssdeep
|
1536:ZIHtII7qSIEXNfq3FQCvUUlLO127YXocnIEdRXQb:ZE+TOc7Y3fvAb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c63cb843e632f836 |
|
VISUAL
aHash
|
001800003c3c3cff |
|
VISUAL
dHash
|
32f031c4ccc8c8c0 |
|
VISUAL
wHash
|
801800347e7e7eff |
|
VISUAL
colorHash
|
380020001c0 |
|
VISUAL
cropResistant
|
0000000000000000,32f231c5ccc8d8e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 90 techniques to evade detection by security scanners and make reverse engineering more difficult.