Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15B5221A19015A63B1263D3E5A3F2A74EFB81C58AC8F6104ED0E5D75C2FE2D71EC1A319 |
|
CONTENT
ssdeep
|
384:e3o5AzFCyCB+mSZ6Nz+mZHVu1EF4tI1pTRHIBmbq:e3o5ALGzSZ6Nz+mZHVu1EF4tIzTRxbq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e1661e9e11e1e96 |
|
VISUAL
aHash
|
00001c1effffffff |
|
VISUAL
dHash
|
1b78743430202024 |
|
VISUAL
wHash
|
00001c1cffdfcfc7 |
|
VISUAL
colorHash
|
070010080c0 |
|
VISUAL
cropResistant
|
1b78743430202024 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.