Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15DC4DA21B610FC27C2035ECF5120D925BB4DF72ACA1A53D6F3845A379B69CB17DB6828 |
|
CONTENT
ssdeep
|
3072:UiX2rdg4ITTKhcaP/hgaOKa5KCqLIPmCNXP:Fs5bLiXP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9616ed68699669b2 |
|
VISUAL
aHash
|
121626040000ffff |
|
VISUAL
dHash
|
766ceccc8c0d4833 |
|
VISUAL
wHash
|
1b3e3e040080ffff |
|
VISUAL
colorHash
|
0f0011c0000 |
|
VISUAL
cropResistant
|
ec9ebcfcccb2f565,56181c1434642524,646230e8e8b8acb8,a3cb65745a706c2a,9a008a72328a809c,4c4cb20323339333,76746ceccccc8d0d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 103 techniques to evade detection by security scanners and make reverse engineering more difficult.