Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T132C3733433886E3EA1C787D4E7767B3953AC8384D61B9198F5B893B14A86C98FC33594 |
|
CONTENT
ssdeep
|
1536:j/sIxsRBJb+HRYToQy3QINNNNsNNNNfNNNzNNNNKNNNNjNNN1c97O:j2KFg7O |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a8552f1dd0aa57aa |
|
VISUAL
aHash
|
120264e474000b19 |
|
VISUAL
dHash
|
b2a28989a4e633b1 |
|
VISUAL
wHash
|
5b32e5fd74301b01 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
b2a28989a4e633b1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 52 techniques to evade detection by security scanners and make reverse engineering more difficult.