Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12DB2D8B1F6A4AC7344B341DDF219E6CBE5536026FF258D252EAC52C977C3CB68A310A1 |
|
CONTENT
ssdeep
|
768:UiW+HOuUS5W5bp5/J0YbayaBR3fKxwsTU:wTxaBkwsTU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed4c9293c16d1e1e |
|
VISUAL
aHash
|
ff9b93f3f38787ff |
|
VISUAL
dHash
|
c9362666463b3b23 |
|
VISUAL
wHash
|
009b93f3b38187eb |
|
VISUAL
colorHash
|
07480008000 |
|
VISUAL
cropResistant
|
c9362666463b3b23,2fb7d65b4d694a3c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.