Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10E92A530A048A93741C7B2D1B6725B9BB3E1D38ACB3316846BF8831D5FD3E64CE16925 |
|
CONTENT
ssdeep
|
384:1HgA5Y09qBoqsvIKwMm9I2LXcuf0roUa87L:m+Y0AsvIKMIAsOLUf7L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92552365d48a5dbb |
|
VISUAL
aHash
|
04003c3c1c102f3d |
|
VISUAL
dHash
|
dcc8d8f4f576cded |
|
VISUAL
wHash
|
24003c7c1c787f7f |
|
VISUAL
colorHash
|
30c00000000 |
|
VISUAL
cropResistant
|
d839e4cca4252565,0008c06d2dac4000,dcc8d8f4f576cded |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 57 techniques to evade detection by security scanners and make reverse engineering more difficult.