Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B4937661F153643A316FA2CBD11E2B1D62C2E38AD7828BDA51F4435CD6F6C907F921AC |
|
CONTENT
ssdeep
|
384:8PDQQ+NG848KGZtSgN9n6C6Lj9uPFMLk8CaUuzmYwLwQjFe5+6mFNJsCEuTUf4OV:wVGZcYu09ML+vY6wiH04UarB/DpnIdn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93916e6a656c6cc5 |
|
VISUAL
aHash
|
000e3e2e7e0c0000 |
|
VISUAL
dHash
|
dc5cdcdcdc18c0cc |
|
VISUAL
wHash
|
420e7e7e7e0e007e |
|
VISUAL
colorHash
|
30000406000 |
|
VISUAL
cropResistant
|
c2e42e0e8e969f9e,dc5cdcdcdc18c0cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.