Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A5A163745203197E525796F4F5F1E36EA2AEEB08DD0B890CB2AD02B237CFC85D8D5294 |
|
CONTENT
ssdeep
|
96:T6Ack8Gk8Enj0SO8oT3payw+essAlC4BkQ:+Ackj9gssGXBj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d1e41be6936c1966 |
|
VISUAL
aHash
|
00ffc3ffffff0000 |
|
VISUAL
dHash
|
8ca6b2b2aaaa3358 |
|
VISUAL
wHash
|
0062dbfffff70000 |
|
VISUAL
colorHash
|
19081000040 |
|
VISUAL
cropResistant
|
4dcc88c8f0888080,272733334b292d33,8ca6b2b2aaaa3358 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.