Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D4B281F0421218A6965BA3F2B1696F1EA8B647C5F7571C29F6F9460DE381C90CF43AB0 |
|
CONTENT
ssdeep
|
768:VF0LoZ5qhDXW1MdGy/vUapfRNc2UrWhK+Raw0ZqQZvVLpo25BYcb4mOC9OAduP0Y:VFsoZ5qhDXW1MdGy/vUapfRNc2UrWhKY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
beb6e2c989989872 |
|
VISUAL
aHash
|
bfa7871f99d9c0f9 |
|
VISUAL
dHash
|
706d297133330d11 |
|
VISUAL
wHash
|
bf07071d9998c0f9 |
|
VISUAL
colorHash
|
07c00008000 |
|
VISUAL
cropResistant
|
706d297133330d11 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.