Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16503E9F2D2043535028349D5F70A735AE36AC099DF624D9562FEC37D86E2FA5E87320A |
|
CONTENT
ssdeep
|
384:01RaESI5HMjl49QPOAVXkVEFFJTfq22o4dR3EytldF0YhwvhDZdlqhggZuLCQPHD:YJHArPOAVUI79YhGXqZumEj/ZG/8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc498dac9e92cf18 |
|
VISUAL
aHash
|
df00c38f83838f8f |
|
VISUAL
dHash
|
37960e3c3b033c3e |
|
VISUAL
wHash
|
df00bf8783838f83 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
37960e3c3b033c3e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 935 techniques to evade detection by security scanners and make reverse engineering more difficult.