Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11BA33CA43A19F96A55F343D350DF2103B279562B540E4C20B351ECAE72BCC9AA077FDA |
|
CONTENT
ssdeep
|
1536:RHWfAXgfbsQJo2h2wV92949tVPTMn5UCkNufo65a8+:c4XkXMA2i9nYkco6E |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ccd877333c12dc6 |
|
VISUAL
aHash
|
7e18181800187c3c |
|
VISUAL
dHash
|
c0f032300810d0d4 |
|
VISUAL
wHash
|
7f7e181800187e7f |
|
VISUAL
colorHash
|
38001000580 |
|
VISUAL
cropResistant
|
c0f032300810d0d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.