Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T194D1F8F152241AFD304787A8FFA07B7E705FD2D7E99B90CC82E8862497C9C48CE55950 |
|
CONTENT
ssdeep
|
96:TGum7Ftx4Grh4qwlYI7VCPGKUjHMV8ohhwAY5bqRe5VtrTq3/ZpTVYV8WsDWUJ7b:s7WY/GKUjHMV8LAAqRe5VtAxhVYV89f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c9873667399c966 |
|
VISUAL
aHash
|
031b1b1b071b0100 |
|
VISUAL
dHash
|
0fb3b3332b33370f |
|
VISUAL
wHash
|
071f1f1f1f1f1301 |
|
VISUAL
colorHash
|
38000000000 |
|
VISUAL
cropResistant
|
0fb3b3332b33370f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.