Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T108E31F717D63A42620AF62CF9127270DA2C2D7CAD76367E565F0821C9AF9C807FE3164 |
|
CONTENT
ssdeep
|
1536:b9bZeMSX5ouj71JkjP2/4/1vt2jDA7S7Ma7e7b7E7f7drnLIkZ65m7tHBWhApW2+:AiEjYYZ4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8493366c3ddee12c |
|
VISUAL
aHash
|
00467e3e1a5a1400 |
|
VISUAL
dHash
|
ccd4dcf0b2b22426 |
|
VISUAL
wHash
|
06767e7e5b7a1402 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
ccd4dcf0b2b22426 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.