Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E21114F180B9E6164741E2A467D2BA24315C8258D36F164197CB92FC03C296ECC8F1C6 |
|
CONTENT
ssdeep
|
24:hR/Crrt3cOwdNXbuLsEEMOdZ+b34BcrbzPea:T8Zcdzbu4TZu5L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f722772a572b5908 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
4904100800010002 |
|
VISUAL
wHash
|
000000f0fcfcfefe |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
2a48481044052508,0000000000010002,0000814145810000,1008303232300800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.