Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B6810F90DED844A2725AD7B8B1E55FCCB2897217D302E9A4F3803694C58F83ACF9D209 |
|
CONTENT
ssdeep
|
48:bTf1ZNvnCQFfSFwZsLJuuT505V5Rn5W5y5T35h545Uu5VWmsjduiLf8SuxPhiu5K:XgQrCSdl/k++nBBxJer |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dc74269b9c668cc9 |
|
VISUAL
aHash
|
0000181818180000 |
|
VISUAL
dHash
|
100030b2b2302000 |
|
VISUAL
wHash
|
34c41adad9b914b7 |
|
VISUAL
colorHash
|
38c03000000 |
|
VISUAL
cropResistant
|
100030b2b2302000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 489 techniques to evade detection by security scanners and make reverse engineering more difficult.