Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1216345B89202177B228705F171D1A78FE2FBDB59DA23EC4CB3AD51122BCDC558B93660 |
|
CONTENT
ssdeep
|
768:Fn7iTn9jRIye/CmCxksptDDmbX2z/T5UUK:FUTXK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8b39e49293cfb09a |
|
VISUAL
aHash
|
0000183c3cbdffff |
|
VISUAL
dHash
|
30b0b27179696169 |
|
VISUAL
wHash
|
0000183c3c7dffff |
|
VISUAL
colorHash
|
00000000188 |
|
VISUAL
cropResistant
|
30b0b27179696169 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.