Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T114E5B77192887A3EA15383D8F72167EA72EA8253DF170A44C3F0963877D7D5ADD23884 |
|
CONTENT
ssdeep
|
12288:yauaDaDaDaDaDaDaDaDaDaDaDaDaDaDaDaDaDaDaDaDax:l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b64c9eadc9b0a2c9 |
|
VISUAL
aHash
|
0200066763670f0f |
|
VISUAL
dHash
|
b6cccc8ccfcf7cdd |
|
VISUAL
wHash
|
4e06076767670f0f |
|
VISUAL
colorHash
|
31002000480 |
|
VISUAL
cropResistant
|
fefcf8f8f0b16362,2d4d4b2a0a4a4ab2,beeee6eee8dad6e6,ffeecece4ed2f7ff,b6cccc8ccfcf7cdd |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.