Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18A83B369A162127B106387F5F415EF16F09AEB0FC72BAD19F2FC639B27C7C109962064 |
|
CONTENT
ssdeep
|
1536:QUBgAzDIyKDbixzyw6brDwivUdjr07Y8hGl:x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f871f6ad01af078 |
|
VISUAL
aHash
|
3f3fffbffff10000 |
|
VISUAL
dHash
|
594a406061434941 |
|
VISUAL
wHash
|
3d2f3f3fff810000 |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
594a406061434941 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.