Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FE6279B19048AD370293A2D1A2B6172FB6D4C347DB4B575293F8D3DE0FD6EA4ED26018 |
|
CONTENT
ssdeep
|
192:g/8r3S313/dn+0SbNp3Pw/cJUuvgHy1Vh/ScDV6Lq5xQrYieqoaBJHL4N2ENxaid:g/8r3S313NCn4mQ/Q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b193390cccc76dc6 |
|
VISUAL
aHash
|
cfcfeffff381ff81 |
|
VISUAL
dHash
|
98994b0826230c2b |
|
VISUAL
wHash
|
0f07efe7c381c780 |
|
VISUAL
colorHash
|
070000081c0 |
|
VISUAL
cropResistant
|
98994b0826230c2b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.