Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T160A29732A054263F1363D3CD7352B72EE5E35289E78A181A56F84B6E87D7E60CD2341B |
|
CONTENT
ssdeep
|
384:Sqy5NbePX/SGmJhL1ZdIIIIIAckJQJj93stvLIWKtjj1IYsOy2+y9BH4cCUIe:Sqy5NbeP+31ZdIIIIIAcu6j93stvLIWe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc3ac3e9c3926938 |
|
VISUAL
aHash
|
f98e868fd1f1fffe |
|
VISUAL
dHash
|
63343c3c33b3c890 |
|
VISUAL
wHash
|
b08c04070b71fffe |
|
VISUAL
colorHash
|
07001000180 |
|
VISUAL
cropResistant
|
63343c3c33b3c890 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.