Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11032B563110C1929C333819D68413A106346D5CFCC5296B0A5A82F7F2FE7F66A7927BF |
|
CONTENT
ssdeep
|
192:PTL67kCPHjbeIj2mEs/riHEs/r6VPhEs/r6VleCsbMZ/mjwgE3w2jJjQF62i0jw5:BCPpprgpr6zpr6zsbMFg9TK9QW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8ebc3393c2630c7 |
|
VISUAL
aHash
|
c1f9e7818b8fffdf |
|
VISUAL
dHash
|
23230c37333ac01a |
|
VISUAL
wHash
|
c399f381838fff00 |
|
VISUAL
colorHash
|
07400000180 |
|
VISUAL
cropResistant
|
23230c37333ac01a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.