Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7C1633191024C3B577B85C475FBBA1E26F88301C6462E50E2FC53DE2BDADB5C967285 |
|
CONTENT
ssdeep
|
96:JBbWBjrBoGObQibuujVpY7e1tAC4AXx0zOnfSL3EAnq6Xm8Z:JOoGOsibuuEe1H4AB0zOnfSL3EIq6Xm+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a41a171d373619eb |
|
VISUAL
aHash
|
061f1f07131fe73f |
|
VISUAL
dHash
|
fcf6f784b7b6ccee |
|
VISUAL
wHash
|
060f1f07071f671f |
|
VISUAL
colorHash
|
000022000c0 |
|
VISUAL
cropResistant
|
a2002032324d1082,fcf6f784b7b6ccee |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 27 techniques to evade detection by security scanners and make reverse engineering more difficult.