Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10FC2F9327114663B02D3C2C9B372636FA1E38649E7460414E6FD839D47ABE58CE7366E |
|
CONTENT
ssdeep
|
768:2ny5NIOhClK+72s/lD4xE6lCFWUU7sOy2+y9BH4c1Ie:bhZ+dhFWUU7sOy2+UBH4c1Ie |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc3ec7c3c12c1c2e |
|
VISUAL
aHash
|
fb87818bcfdfdbfe |
|
VISUAL
dHash
|
633937371d353398 |
|
VISUAL
wHash
|
b187818d898d99fe |
|
VISUAL
colorHash
|
07038000000 |
|
VISUAL
cropResistant
|
633937371d353398,26243336775a194c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.