Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7537231A941AC3B41CF96C8A532577A72A94385CA030684FAF583F95FEFC6DDA37049 |
|
CONTENT
ssdeep
|
768:I3sIx/j/MC/WScI+vBuNfdgO5bkwqrLftUf790:ysIxgwWSAUHbDq/fq790 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
98986477cb0df836 |
|
VISUAL
aHash
|
080c1f3c3c9c0070 |
|
VISUAL
dHash
|
59753170717070a4 |
|
VISUAL
wHash
|
0f1f1f3e3c9c00f4 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
59753170717070a4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 115 techniques to evade detection by security scanners and make reverse engineering more difficult.