Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T151C10E34E1141A7A810F86CCA7B4633B03F7D288D55A0A0DE6BDC7A477E1D98DD9F198 |
|
CONTENT
ssdeep
|
96:TCFLAq4FSc3Gq4QKfuet+ime+MRn1Ea5h9lm:CAq4FSq4Bfuet+imejRn1EaTW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9fc72ca3ac28cd2 |
|
VISUAL
aHash
|
90183c383c183800 |
|
VISUAL
dHash
|
55b2f2f2f1f1f1f1 |
|
VISUAL
wHash
|
bcd8fe7c3c383c00 |
|
VISUAL
colorHash
|
31e00000000 |
|
VISUAL
cropResistant
|
8a9abaeebab4a09a,55b2f2f2f1f1f1f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.