Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T178334E719142482B9687A2D5FB781B5EF2C29356CA031D09BBF18B1F9FC2E64FD26170 |
|
CONTENT
ssdeep
|
1536:TieRsN8XgRBkGvddM709sc9Y840if6Qthf0Xvqvt0ZY38oNyypWfF:Tfs+YNRvqL5Ot |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b846e40df86ff20 |
|
VISUAL
aHash
|
7c023e3e1c0c0081 |
|
VISUAL
dHash
|
a4166cf0f879f945 |
|
VISUAL
wHash
|
7e073f3e3e0c1c81 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
a4166cf0f879f945 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 267 techniques to evade detection by security scanners and make reverse engineering more difficult.