Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15C22DA37F11866250AA74299EBC1E6DCE327C25DE6314681A1D9C01D7AC1EF09AF33DE |
|
CONTENT
ssdeep
|
96:hohJmKohzohbC7aR1sYtxITwkFiNa0lvxz6qfiQj22AHDIAfFEaK9UZlL/DWEfMz:BUdyvGvp6U2fjzFEa7HWEfMmUU8VCoZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc3a40c9c9cbcb4b |
|
VISUAL
aHash
|
9987879f8fdfffdf |
|
VISUAL
dHash
|
333d2f331b373536 |
|
VISUAL
wHash
|
89878fc381879f93 |
|
VISUAL
colorHash
|
07201000600 |
|
VISUAL
cropResistant
|
333d2f331b373536 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.