Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T193B210243442E82F49C757D46131536EB3A6D781DA134AC1B6E1C3F94BEBDA8EE33609 |
|
CONTENT
ssdeep
|
384:nKZkURk8/69Olkp/kpjGq5M9mjGvEygYlYjft:KZkrA5YEygYKF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
df8f2231f8362b88 |
|
VISUAL
aHash
|
003c3fffff2a04c0 |
|
VISUAL
dHash
|
85e06020b25aec85 |
|
VISUAL
wHash
|
003c3fffff2a04c0 |
|
VISUAL
colorHash
|
0e000038040 |
|
VISUAL
cropResistant
|
9898b098a1391e96,c8c0c1c283c1d0d9,3074d434e1ca69e2,9090c6ded8303196,31617133333230c8,82000c5e2e2e0082,85e06020b25aec85 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 139 techniques to evade detection by security scanners and make reverse engineering more difficult.