Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2136F2090A7592B05FB80C656B2AB6671F19349C71242D6BBFC9BFE13CEE61FC0B505 |
|
CONTENT
ssdeep
|
768:7PZdXI9UAveejezexe/e/eNeMese0ePeHeXeJe/e5eFebeneWNOeewezexe/e/el:nXIOAveejezexe/e/eNeMese0ePeHeX8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fb7b464636323909 |
|
VISUAL
aHash
|
00f88180ffffffff |
|
VISUAL
dHash
|
28d31b19650c0e2a |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
0b000038000 |
|
VISUAL
cropResistant
|
511b191d464caa2a,c22929c225054b4b,0f2b71313971178f,4151515d69695053,4170307445555111,0100253131710001 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 38 techniques to evade detection by security scanners and make reverse engineering more difficult.