Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12733D9309811ED3B41DBD6C45276572B62E6834ADA130689BBF883EC1FDBD69CE33215 |
|
CONTENT
ssdeep
|
1536:2s2R/sXXNs2BsndZmJPMl5MWMTXuYh0793om:275MWMyYh07Km |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8f0232357a9dad3 |
|
VISUAL
aHash
|
6140dcd8b8996300 |
|
VISUAL
dHash
|
df8ea9327273cb51 |
|
VISUAL
wHash
|
6140fcd8bebb6318 |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
8c9873c4808a9627,332b6b64add9193d,c7c94d4b6b5bdac6,323bab0a26b55567,1f8f9c79caa2c4cc,0901882b2312c202,df8ea9327273cb51 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 82 techniques to evade detection by security scanners and make reverse engineering more difficult.