Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DA937C33421975270537C2D520B95B37E2969E5FFAA70B010EECD7FB2BEACA0755A009 |
|
CONTENT
ssdeep
|
768:DIe6Xbi4oxZ/DFTksPhwfj5I2IEBa4QuViRq1:EJpKZRTksPS9I2IEBa4QuoRq1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f5870af4178dea06 |
|
VISUAL
aHash
|
ffffffffe6c00000 |
|
VISUAL
dHash
|
224b433a1416b2eb |
|
VISUAL
wHash
|
ffffffcec0800000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
22c2631a3a0417b2,0143061c30e3838b,09cb06ccf83107cf,c0d084949195a1a1,34040d1692e14bbb,8c4f0998382167de |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.