Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EDB2A73212442E3EA5178BE9F6B4733951AED24DD22B852CF6FD02B25BC6D45D8332D8 |
|
CONTENT
ssdeep
|
384:Fipu/oGDhHeYJcYEUmYjpwt5ft3/gRzjTrucd/HYxYb0YX:FipuhDhHeYJcYEUmYlGJGzjTrucd/HYO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccf323371198ace |
|
VISUAL
aHash
|
c0fefcd890000000 |
|
VISUAL
dHash
|
907060301030b0a8 |
|
VISUAL
wHash
|
f8fffcfcf000004a |
|
VISUAL
colorHash
|
38000e00000 |
|
VISUAL
cropResistant
|
907060301030b0a8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.