Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T139D144E1C008DD37032246D5F7F56B1FBA96C359CB02098453F842EB9BDBC70DA16A99 |
|
CONTENT
ssdeep
|
96:TkJSHkh4lzH0X0eGBrUR/wvFheNXBHFfexXIz/Nt7l4qQPJ:QJSHkh4lzH0XsBrQJDcqz1r4qQR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e763b330b032e363 |
|
VISUAL
aHash
|
ef203000000000ff |
|
VISUAL
dHash
|
0dc0c03016321604 |
|
VISUAL
wHash
|
fff0781c0018c0ff |
|
VISUAL
colorHash
|
01007000000 |
|
VISUAL
cropResistant
|
0400040404040004,a0a0a0a0a0a080a0,8282828282828282,8282828282828282,0000000000000000,0dc0c44016163206 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 55 techniques to evade detection by security scanners and make reverse engineering more difficult.