Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B8210383180767790C7D6E5AA74A76FF3D1C28ACA279B0AA2F883495FDBC45CD90254 |
|
CONTENT
ssdeep
|
192:3TOrfCgIK5tX6bq/fqdXyex59u//rZ7oaLbupbQ2NJ5v6tYCVMhf:3abCgIm6iFyQ2NJl6tYCAf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d0252db1b0e5e997 |
|
VISUAL
aHash
|
620070e4ece8f0f0 |
|
VISUAL
dHash
|
8a71c08c8890c0a0 |
|
VISUAL
wHash
|
663870e47cf8f0f0 |
|
VISUAL
colorHash
|
38002400000 |
|
VISUAL
cropResistant
|
8a71c08c8890c0a0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.