Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11FE3E9B121181A63D6979345DBA0A3DB20BD41ACB8B154149CFC81CF9FE6CBAD43D3B6 |
|
CONTENT
ssdeep
|
1536:/bg4V544mmH44qD9mf3G8/6r56brKsJJJHzp:/bg4V2G3G1U/Ks719 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b564cf986309cec6 |
|
VISUAL
aHash
|
c292b301031f3f3e |
|
VISUAL
dHash
|
9e26668a8e38786a |
|
VISUAL
wHash
|
c2f2f203031f1f3e |
|
VISUAL
colorHash
|
180000001c0 |
|
VISUAL
cropResistant
|
cccd25b25315b435,9e26668a8e38786a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 247 techniques to evade detection by security scanners and make reverse engineering more difficult.