Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15B52EB7190099E371293A2D1A6B6231FB6E0C347CB4F575253F9C3EE1BD6EA0ED62109 |
|
CONTENT
ssdeep
|
192:4/8cIKDdi+0iJTNp3PbAbJUuvgHy1Vh/ScDVzLq5xwYrbOY0y3uVZ4gAk3NgdXF/:4/8cIKUUTO4JwYkOgAgNgL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b993913c6cccc764 |
|
VISUAL
aHash
|
cfcfefdb81c3c3c1 |
|
VISUAL
dHash
|
981b482b2b17370b |
|
VISUAL
wHash
|
0f8fefc381c3c381 |
|
VISUAL
colorHash
|
07000008180 |
|
VISUAL
cropResistant
|
981b482b2b17370b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.