Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A73F831F164263B068783E9F7207BAD61D3A38EE9910124F6F647783BA3CA4FC46595 |
|
CONTENT
ssdeep
|
768:NzcX4Fh4/uDbjW1Tkpt1Zn0d55rOp8pIdsXF:qI4/uDbjW+wo8pesXF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc431cc31f2e313e |
|
VISUAL
aHash
|
00ff8786ffff939e |
|
VISUAL
dHash
|
cc941c1ce4162736 |
|
VISUAL
wHash
|
00df0400ffff938e |
|
VISUAL
colorHash
|
07001038000 |
|
VISUAL
cropResistant
|
cc941c1ce4162736,7365cd536f3d3d2c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 73 techniques to evade detection by security scanners and make reverse engineering more difficult.