Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D4621E34A079AA77028FA1D5A6A26F1AB2E3C347C75317D612F8934D0FD7C65DE53208 |
|
CONTENT
ssdeep
|
192:Obi6ylme+hgPH7EkF7SHc7k667vx+7WAZFW2PhQ/QlQEQK:Wi6yIWDbm+/ZFW2p8kJ/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b9c65279255a7159 |
|
VISUAL
aHash
|
ffffffab03890808 |
|
VISUAL
dHash
|
d0e4515313331179 |
|
VISUAL
wHash
|
ffffff2301890800 |
|
VISUAL
colorHash
|
07401000600 |
|
VISUAL
cropResistant
|
d0e4515313331179,000000c040400000,0f71ec6535339d5f,ac29291cad2d2c3c,2ec7e3c86969666c,1b7c7a76753c8f83,7c72736d7973574f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 21 techniques to evade detection by security scanners and make reverse engineering more difficult.