Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E1436732C3115502A0F6D1D9F1279B4663918289C60B0BB4B7EC67BEFDCFCB57A21299 |
|
CONTENT
ssdeep
|
1536:/+eKegeMegepelneeeD6ewkPeeeeeeOmA0eoVeLeAZSjU1keeeexeGoOeeeeeeef:fjreejWeHfImGs68A3ZiHq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed3436e991cb9286 |
|
VISUAL
aHash
|
c381b1f9fbf9b9fb |
|
VISUAL
dHash
|
2b27634313537353 |
|
VISUAL
wHash
|
818101f9f9b9b9b9 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
2b27634313537353,899964f1312e2b22 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.