Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F031CF4535022F8504397F0F762FA35B67BE9BCEA67C654B3E88650B7C5C8C89849A0 |
|
CONTENT
ssdeep
|
768:B/oULm/4PTP/mh0nJQ6jebwMiqUsY5WSzDofavPQpB958T/Nu:B/oKgsWQebwDWSQCtTE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
858c72683de39ec9 |
|
VISUAL
aHash
|
00187e7f1a18646e |
|
VISUAL
dHash
|
b2e1e092b232cccc |
|
VISUAL
wHash
|
583c7e7f1a00666e |
|
VISUAL
colorHash
|
3040000a000 |
|
VISUAL
cropResistant
|
6a2c172626161464,a280ab230bb882a2,b2e1e092b232cccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.