Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10342EB71306CED371283A5EAA2B56B5F32E1C345CBA313515AFD83AA4BC2CF0DE15496 |
|
CONTENT
ssdeep
|
192:5hvEREXsQim1E7YuyAbOBq7C0zXiJGQZ8hMR41YER:4REXsQim1E0umEpWHZ2BR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1313131cccecece |
|
VISUAL
aHash
|
cfcfbfffffffffff |
|
VISUAL
dHash
|
9a9a603804000430 |
|
VISUAL
wHash
|
0f0f3f3f3030303e |
|
VISUAL
colorHash
|
07038000000 |
|
VISUAL
cropResistant
|
9a9a603804000430 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 71 techniques to evade detection by security scanners and make reverse engineering more difficult.