Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E6274A1915638265537C1D8F561A7DFACC18ACCD603C791D2F8A33E2AC4DBABA43358 |
|
CONTENT
ssdeep
|
192:jXQPeKzy9Tb9vvux4/hwMXJLVTUTsjToULyAATFlTC/icluPA9c2wf8Ks:d9HgCAep+3ZlYiclj9cs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d774744e8b8b8a8a |
|
VISUAL
aHash
|
0002efffffffffff |
|
VISUAL
dHash
|
f0864d6969696968 |
|
VISUAL
wHash
|
00003c3c3c3c3fff |
|
VISUAL
colorHash
|
07003000c00 |
|
VISUAL
cropResistant
|
f0864d6969696968,0020909080308888 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 45 techniques to evade detection by security scanners and make reverse engineering more difficult.