Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15203DA359228A33F865B87DCE926BB60904BD1CEC72B850471F506A56BE3DF1F50C1AB |
|
CONTENT
ssdeep
|
384:GvR01OzNPe6LEkzInVmTCesSa/Ed9dxFx28Y5ak1YtWqAAARRLEq+yeTgzLHvxLN:GvC1EPeScni9mJMk1YmAARRZ+SzLHJLN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f34cb38c23cc99a3 |
|
VISUAL
aHash
|
ff000000ffffe7e7 |
|
VISUAL
dHash
|
45f0603013144d4d |
|
VISUAL
wHash
|
b8000000ffffe7e7 |
|
VISUAL
colorHash
|
060000003c0 |
|
VISUAL
cropResistant
|
0060616b61008040,24d69a38d4ceaa89,08a2a36424a97930,41d480a6ba80d4c0,691616140d4d4d4d,8460707020303201,16860226024b0b8e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 46 techniques to evade detection by security scanners and make reverse engineering more difficult.