Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EFD24F302351192E51C387B1F3A17B6E92A9C7C8DE1B4A6DF3BCC1662FC5C5ACD59260 |
|
CONTENT
ssdeep
|
768:OR944fjZI0dHYYhsC2uSI08RIp7JDayrlEvL:u44F4DhI08RB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d8e8e3a9cac9c8e2 |
|
VISUAL
aHash
|
ffffdf9800000000 |
|
VISUAL
dHash
|
2b1431313373584c |
|
VISUAL
wHash
|
ffffffdd00180000 |
|
VISUAL
colorHash
|
0b007000000 |
|
VISUAL
cropResistant
|
240bcb2b2bcb0401,0215313133735c44 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 15 techniques to evade detection by security scanners and make reverse engineering more difficult.