Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1350286F39194C5265B3193D8B8107B5CB11BB41ACDC48D8EE3948B9E53E2DE0CD8A25F |
|
CONTENT
ssdeep
|
192:hoq5SgVKOSprlE04du+ryP2iF5CIUdxqm5tsdlFcWFX5PF2FlFJFRF5fFhwHFdFv:hoU25CIbPtXjYPbT5thAXV0l0GeYHweO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93131125e5ede527 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
9298490020000000 |
|
VISUAL
wHash
|
0000000100000000 |
|
VISUAL
colorHash
|
17000038000 |
|
VISUAL
cropResistant
|
0022020000000000,4242a5b898692906 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.