Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F1C3D750DA716A24D723838DC760337940BBB1EC6F270414966457B5FB6AD8EFC3A2E8 |
|
CONTENT
ssdeep
|
1536:Cguep5aOslGUx1eDIae69hmvuEymXBWovtRpwdKDC7blDteiV:Cgue+163mmlUc7B5eg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
969acb73323224cf |
|
VISUAL
aHash
|
443c3e061600303e |
|
VISUAL
dHash
|
8df8e4aca494c0ec |
|
VISUAL
wHash
|
443c7e4e5e047c3e |
|
VISUAL
colorHash
|
30002008040 |
|
VISUAL
cropResistant
|
8df8e4aca494c0ec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 88 techniques to evade detection by security scanners and make reverse engineering more difficult.