Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1586360226A00DE2915DF4ACC81B3626612FA9749D51700CAFDB9C3F947BFCACD67B901 |
|
CONTENT
ssdeep
|
768:Gepl1e+SyxHX53R6CiiL8FehPh5SMcx1CsIx/jBUf7y:xpa+SuJ3RGGP+Mi1CsIxS7y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cecbe12cb1658663 |
|
VISUAL
aHash
|
ff383c1c1c1000ff |
|
VISUAL
dHash
|
91e171b975646494 |
|
VISUAL
wHash
|
ff383c5d1c1000ff |
|
VISUAL
colorHash
|
07480008000 |
|
VISUAL
cropResistant
|
609094616161e1e1,9018c5ccdaba9494,33b8b03131b1b1b9,2ff565696828c28b,193129bd8930341c,a36383f2c1d4c113,242486d4949490b4,61f161b975656486 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.