Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17FD166739014D81A1EB7D188F7C0E08CA1A6C25BF73188D7B2D4922F6BC4DF8956232C |
|
CONTENT
ssdeep
|
96:QiCHaR1sYBlnbYz+/fMmORR1E8VConHGPI1VZIl:QWdBmq/fMmUU8VCoHK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf0b91906e6ef0f0 |
|
VISUAL
aHash
|
3d3dff0000ffffff |
|
VISUAL
dHash
|
79512a6565004500 |
|
VISUAL
wHash
|
0038f80000ffffff |
|
VISUAL
colorHash
|
07200000c00 |
|
VISUAL
cropResistant
|
79512a6565004500,04265e2c4c491b5a,9a5b9bb64e1eaeae |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.