Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11523823650005F7B11D381CABBB47B4EF2C6E298CA57569693F8836E07C6ED0CD326A5 |
|
CONTENT
ssdeep
|
768:qfxGdXPUe+ItxFRlfi7MG8/I6jmzyHqJNssDHYq:PN+ItPLK7MG8/pjmzyCqs75 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
922de932d22cdba6 |
|
VISUAL
aHash
|
0000003c2c04ffff |
|
VISUAL
dHash
|
def271e86ccccc11 |
|
VISUAL
wHash
|
0000043e2e7effff |
|
VISUAL
colorHash
|
06e00008000 |
|
VISUAL
cropResistant
|
ac6864c1c9d1c6e6,eeccf6f87cf66fff,b0a8aaf2a2b80080,bdf26a6531f3c993,cc00090019190909,def271f9e86cdccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.