Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T173B3EBA0A08C0E12A1524751AF90ABF721A651ACFE718118AEFCC3D75FC1DEF583A5D7 |
|
CONTENT
ssdeep
|
768:WJ44Yl0440l8uiUlnotS3HThDbMTIXmioXp68w8sxrQv6cbmW1O0l8:k44544nmoGbMEXmi6li |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea66992193a7998d |
|
VISUAL
aHash
|
e3c0f1e1c1c183ff |
|
VISUAL
dHash
|
9b25a5e58f8f0f38 |
|
VISUAL
wHash
|
e3c0f1f1c1c1839f |
|
VISUAL
colorHash
|
12007200000 |
|
VISUAL
cropResistant
|
d45531d62a26b5b9,9b25a5e58f8f0f38 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 148 techniques to evade detection by security scanners and make reverse engineering more difficult.