Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A502667132C62ABF12A34AF2F2D0AB79A0E5C70DC917C589E3FC869667CEC908D54714 |
|
CONTENT
ssdeep
|
96:lzcVSFjneWrAmTrzUMK2rHH9Lt/1Fkkk5zskHgSkf06hub5sghBkMhsvzTGaPtNb:NZU27H9zxkVdT5NNUvG4n9Asz1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88d6a2fd22d992d3 |
|
VISUAL
aHash
|
ff383c1810181801 |
|
VISUAL
dHash
|
966179b2b0b21229 |
|
VISUAL
wHash
|
ff3c3c18181818ff |
|
VISUAL
colorHash
|
38000018018 |
|
VISUAL
cropResistant
|
36263636f676fa7a,966179b2b0b21229 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 25 techniques to evade detection by security scanners and make reverse engineering more difficult.