Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10D42C7F297A5583EA577C3C59BB9B32C30EA909ED29B0110C6EC879C46C6E58FC33490 |
|
CONTENT
ssdeep
|
192:fIvqCI1Jy+kawgnXR7qz4lP2BZisaZ0YYFNa33qVZ:fIvqOMUz4luzLaZ0Y3S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a7e9b8821616d6d |
|
VISUAL
aHash
|
9c9ca004303c2c0c |
|
VISUAL
dHash
|
393d668da4a9a9a9 |
|
VISUAL
wHash
|
80dcd044747c5c5c |
|
VISUAL
colorHash
|
38010000c00 |
|
VISUAL
cropResistant
|
393d668da4a9a9a9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 142 techniques to evade detection by security scanners and make reverse engineering more difficult.