Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110A1AC34504ADA732292B2D2A6792B1FB3C0830BDA135A2153F8D3DE1B96CD9DC7746C |
|
CONTENT
ssdeep
|
48:SOq5Jc6+Hw881AXl4272E2b2N2u26I25S2l2Vi12Kh2dsH2xD2ph62Xl2du2RX2Y:mjI1ZHj5e |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
801f3f66a5c3c8ec |
|
VISUAL
aHash
|
02047f7e7a70e000 |
|
VISUAL
dHash
|
fcfcf0d0b68680e0 |
|
VISUAL
wHash
|
06067f7f7f70f000 |
|
VISUAL
colorHash
|
00031000200 |
|
VISUAL
cropResistant
|
fcfcf0d0b68680e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.