Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1314395B38285AC330273D5C97275532FB2E2518ECE874B8663FC839A9BDACD6EC15445 |
|
CONTENT
ssdeep
|
1536:Kc44tMvT4lCLZw9Rv1+esxbDFhx5i8N/0:KYETThxs8N8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b838c74637477439 |
|
VISUAL
aHash
|
00df8f8f8fcfffff |
|
VISUAL
dHash
|
ccb11f3b3f37002a |
|
VISUAL
wHash
|
008d83838387fffe |
|
VISUAL
colorHash
|
060020001c0 |
|
VISUAL
cropResistant
|
b1311e3b3f36082a,842bd4d4d4d42244,1f17073332173317 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 224 techniques to evade detection by security scanners and make reverse engineering more difficult.