Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11312B8246084E527071396DCF582FB48A587733EEE0385F6E8AA37B505E5DA7C4F5823 |
|
CONTENT
ssdeep
|
192:m5h4GLE0mOTpDWnCmeSme9qVyjriFR3dMKk0e7PD++RpLA2Yy4I2pNi5Q7K:m5h4GLE0/JpSpk6zzD+wQ2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b20fd330cd32cc37 |
|
VISUAL
aHash
|
07070707078707cf |
|
VISUAL
dHash
|
4d2d2d2f2e8d8d9e |
|
VISUAL
wHash
|
0707070707c747ff |
|
VISUAL
colorHash
|
1b400018000 |
|
VISUAL
cropResistant
|
4d2d2d2f2e8d8d9e,7179d4dcdad2f638,a0a0a2a292cac464 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 144 techniques to evade detection by security scanners and make reverse engineering more difficult.