Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E4230A278005A172A4769FAE6DA6F0C944687CACA405FC5ADFCC2A953F1DE17303778 |
|
CONTENT
ssdeep
|
192:PHbf00+AmYZa65kBOZahoEdtN+Ku6DERKYR7KlK+5r:vb335y/5NLkoUD+p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c1979e326264ed9 |
|
VISUAL
aHash
|
00081810ffffffff |
|
VISUAL
dHash
|
0692b0245a200000 |
|
VISUAL
wHash
|
000808003fffffff |
|
VISUAL
colorHash
|
070000081c0 |
|
VISUAL
cropResistant
|
0692b0245a200000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 635 techniques to evade detection by security scanners and make reverse engineering more difficult.