Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA33ED728086653B42A3F1D1F2365B6A73D6C249CAA3075293F8D31D4FDBE62EC63611 |
|
CONTENT
ssdeep
|
1536:1eeefeeeleee1eeeCLeeefeeezeee1eee6WxG:0IWxG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f04a3eb469b4c88f |
|
VISUAL
aHash
|
0040585a62e6c7c0 |
|
VISUAL
dHash
|
d494b39296948c9d |
|
VISUAL
wHash
|
404279587bffc7c0 |
|
VISUAL
colorHash
|
30200018400 |
|
VISUAL
cropResistant
|
f8fcfcfdcdcefcf8,e7e66cddf184e4ec,1cdc7cd69c3cebc3,0010084c4c0c1008,d494b39296948c9d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.