Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1830434235604A82601BBC6D820765736D1FA9F4FF6530A45BEACC3F617EEC68E537118 |
|
CONTENT
ssdeep
|
1536:ZbP95Jw96Rw2Fa1QlrBnPj3Dg/R78vz3TU+Ooimw8azJVLbhbm2yYe141F7916M:cy5XIow8afFy2yYE4r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
916e916e95316e93 |
|
VISUAL
aHash
|
02183c003c004e4e |
|
VISUAL
dHash
|
d6f070e86561989c |
|
VISUAL
wHash
|
7e3c3c183c2c4e6e |
|
VISUAL
colorHash
|
18008000e00 |
|
VISUAL
cropResistant
|
c0964b0e07616401,d6f070e86561989c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 147 techniques to evade detection by security scanners and make reverse engineering more difficult.