Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12471A5B730484E3A1B6BCAD8FDC4F60A9053C1AAC4A461C8D0D976DD6BD1EF69423349 |
|
CONTENT
ssdeep
|
48:+HBDGueuNIXDaeLRXcGTQ+MkmIuoahKm4liOI7vjCfwJIXkNDFy/q0HU:2TBaTGwQrCaaih7vjCIdO/q0HU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d49c2d2d096d8797 |
|
VISUAL
aHash
|
00807e7e7e7e0000 |
|
VISUAL
dHash
|
3312ccc4ccc40310 |
|
VISUAL
wHash
|
08d0fefefefe0000 |
|
VISUAL
colorHash
|
38001018600 |
|
VISUAL
cropResistant
|
3312ccc4ccc40310 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.