Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14DE1BA28B446382749338AE1E8C92F14B6E3BB3EC74C951193B427598FCBDEDA914734 |
|
CONTENT
ssdeep
|
192:J39zb1gSVliHNtoDonD9pL8R34RrAW+wt1ZvEr:F9/Xitt4oD9m6m7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1e633e619cc998c |
|
VISUAL
aHash
|
c7c3ffffffe70000 |
|
VISUAL
dHash
|
8e8eb2b2b20e265a |
|
VISUAL
wHash
|
c3c3ffffff000000 |
|
VISUAL
colorHash
|
07400600000 |
|
VISUAL
cropResistant
|
8e8eb2b2b2b20e32,9b834573474f3170,3232304c0c5e5a58 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.