Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17B639420E2325134534F4BBDB1909F1E73AEB2029701FCA99A2719D61D8F9B9F4C7E16 |
|
CONTENT
ssdeep
|
1536:TUgTLAXQ6F9gTLAXQ6F4TYqPee4eTeeVVkeeuUfeeteU:JLAXQ6oLAXQ6K8q0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e3b24d984d9c65b2 |
|
VISUAL
aHash
|
fee7e7e7e7ffff00 |
|
VISUAL
dHash
|
880c0c080c040016 |
|
VISUAL
wHash
|
5ac32727070f3f00 |
|
VISUAL
colorHash
|
07006000040 |
|
VISUAL
cropResistant
|
880c0c080c040016 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.