Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13AE153719241D97E4152D2E6DB153B2E31EB85FCEB53139102EC4BBE6AE3C90DA39A00 |
|
CONTENT
ssdeep
|
192:Ek4dhaayg01HXyvRDbUxhxXhgDVZ9y5v9:Ek42Lg01HC53ohxXejMB9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3b4bc339c64c366 |
|
VISUAL
aHash
|
47e270242c6c203c |
|
VISUAL
dHash
|
8c4cccccc8c9c5e1 |
|
VISUAL
wHash
|
47e7f42c3c6c303c |
|
VISUAL
colorHash
|
38001000180 |
|
VISUAL
cropResistant
|
94047bb9be7c5353,0000001606020000,8c4cccccc8c9c5e1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 66 techniques to evade detection by security scanners and make reverse engineering more difficult.