Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1754139214823947AAB1B5ED6A9652B1B7596CF0DEA3318101AAD23FD0FCAE808B59446 |
|
CONTENT
ssdeep
|
48:T3buH5XyZ2hsZP2J66qU4Y0fC3a5DY3ZsOg2rTjxYm:TLuN22hs92J66qU6aLm2r5Ym |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1cece3126c631ce |
|
VISUAL
aHash
|
ffffcfc7cfcfffff |
|
VISUAL
dHash
|
20189c9c9e9a1c20 |
|
VISUAL
wHash
|
0c0c040004000c2c |
|
VISUAL
colorHash
|
072000c0001 |
|
VISUAL
cropResistant
|
20189c9c9e9a1c20,8080808080808080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.