Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144E2CD316804EE2701DB59C85632566662FA8346CA231689FFF4C7FA5BAFD2CCE73105 |
|
CONTENT
ssdeep
|
384:srsJO5xVZjqTSYNcSSRtVLnCXRF/PVU9roUa879ft:srsIx/jhSSF2/PJUf79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc9c43334779361c |
|
VISUAL
aHash
|
00ff9f9bd7c70020 |
|
VISUAL
dHash
|
44623237360e4a61 |
|
VISUAL
wHash
|
00bf9f9ff7c70020 |
|
VISUAL
colorHash
|
06200000180 |
|
VISUAL
cropResistant
|
80a480cccc80a4a3,6232363736860e0e,3c9fcbe6e4e9c1c1,8db8f0c8e898a28c,444b623236373616,12471b4783939f9f,fb79f353972d79f1,3736861e0e906965 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.