Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T151039571E1118D3F416392D5E3F2A73A22A99385CE0205B593FC077E4BEAE9CBE57240 |
|
CONTENT
ssdeep
|
384:pFzgcFabxVl3jp2IXDVpqGQ4gq6knvWlXsD61egCbh0Q:DZabxVJp2IXTq4g3kgIRbhf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3c63c38aa39b9c6 |
|
VISUAL
aHash
|
01707c7c7c6c0000 |
|
VISUAL
dHash
|
1de4c8c8ccd868c1 |
|
VISUAL
wHash
|
85f4fc7e7e6e0001 |
|
VISUAL
colorHash
|
38000e00000 |
|
VISUAL
cropResistant
|
1de4c8c8ccd868c1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.