Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C4B34EF43604BD2A5EA383A6609B2512727C1317E40D8C20F174ED9EA6EDC8DA477FE5 |
|
CONTENT
ssdeep
|
1536:S4OmYH5I8/CLqnZbU1RSs02ObI/i3UwLVCcuGOjjRn3:SfmYQod2OMdW5uGOt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc99c32cc3c31c6e |
|
VISUAL
aHash
|
fd9b9fff9193e7e7 |
|
VISUAL
dHash
|
413232282333cc0c |
|
VISUAL
wHash
|
bd8b8b8f919f20c2 |
|
VISUAL
colorHash
|
07000000e80 |
|
VISUAL
cropResistant
|
413232282333cc0c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.