Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11A837632E3931913907BD1C9B171471923918B89C7134B7567BD27BAFACECB63622398 |
|
CONTENT
ssdeep
|
1536:MAAeHizPrMeeeeJceraw5epevepeKepe7e7H7ZeeoepeseJehe+xUNgXQQxMzGQ2:rbtcworpiJUtJ9JAJHJzo0AmTn3JzybA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e926613c3e93cc96 |
|
VISUAL
aHash
|
c1a1f7c392eb6969 |
|
VISUAL
dHash
|
2b27641d26d2dbd3 |
|
VISUAL
wHash
|
c180ffc390cbed68 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
2b27641d26d2dbd3,8280175763397141,202626d666483e2e,6124b698a3959d9b,1a1140004000008a,1a05c0008040059a,ce4b5878696b3121,741030cc18491c94,d7693248cccc442c,9686d0ccc69282e3,9894400041280598 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.