Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DDC3D8F1B5413836615B87CBE236BA0EB1C1D28ACE8545D8D2F1335CDBF2D90FAA5249 |
|
CONTENT
ssdeep
|
1536:eHVzsfgAZRTSAHQEBLkPWxBb7DPuRHDrJ42H:eHVsxkPWx17DP2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6d9392649b85c5 |
|
VISUAL
aHash
|
fffbf181c1f3fffe |
|
VISUAL
dHash
|
c416272727262800 |
|
VISUAL
wHash
|
fef0f0808090fcfe |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
c416272727262800,4d8d17379332554d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.