Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13E13F7B2B148607F6113D3CAD216351CB599C1EEDAE91362B7F0813CA6F3DE0E558B89 |
|
CONTENT
ssdeep
|
384:NJXCBUUP64DH/FbipmnTGJd1m1+DEB0ZTwLEEP5m5oVs2OCZsUxDixPfDo1MI8HK:NoUV4tcEq7k1R2RIPPhs2OZS83ocMH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcc99e36cd863831 |
|
VISUAL
aHash
|
9f8383fbc3838787 |
|
VISUAL
dHash
|
202b3b32122f2c3c |
|
VISUAL
wHash
|
9f8381f3c3838787 |
|
VISUAL
colorHash
|
07001018240 |
|
VISUAL
cropResistant
|
202b3b32122f2c3c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 236 techniques to evade detection by security scanners and make reverse engineering more difficult.