Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED14B670E5F0163B105F6AC5F3126F5AE193D387DA8203F983F94664ABA5CD5BE03298 |
|
CONTENT
ssdeep
|
3072:+3eVdXEQs0lDNPGBH5/7V9eJE7v5cejFO2Fl:lnlBDNEH5/7V9eJE7v5cejFO2Fl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6c999c666391993 |
|
VISUAL
aHash
|
ffff8f81e7c78787 |
|
VISUAL
dHash
|
c0183b2f4d2d0f0f |
|
VISUAL
wHash
|
efef858187878183 |
|
VISUAL
colorHash
|
07c00009000 |
|
VISUAL
cropResistant
|
c0183b2f4d2d0f0f,0000002020800000,202120c0e1842420 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.