Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11413B532A191653B42E385D2B2B613AF73FAC28AEA13470147FC835C9BC7DE4ED29515 |
|
CONTENT
ssdeep
|
768:1II+hAQPtXysMomJLvJXnLxfgxdhNBFcI+uigYgd0vG6JeXJRWbP03L6asJbuEHS:1IIo3ZDPaTFxANBFCuJ0vbJeXDWbc32G |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce803b24fb82df8c |
|
VISUAL
aHash
|
b9003c3c1018008d |
|
VISUAL
dHash
|
23b27161b660e059 |
|
VISUAL
wHash
|
ff183c3c183c3c8d |
|
VISUAL
colorHash
|
38000000c00 |
|
VISUAL
cropResistant
|
23b27161b660e059 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 132 techniques to evade detection by security scanners and make reverse engineering more difficult.