Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14B23CA3218C82F2B529393C4B361D64BE3D1554DE27ACA4AF5DAC32B59C5D84C83EF68 |
|
CONTENT
ssdeep
|
768:rHIRf6SQfWh6wNBiWwGsjwsAJZiCy8Eh9+MASayqEF4o5303li58mx/tdpiElEGH:rHIh6TsNBiss8JwJ8EhuSayqEF4o53ik |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946b87b4e9c6b087 |
|
VISUAL
aHash
|
ff000000060e362e |
|
VISUAL
dHash
|
73f0ccf09c9cecdc |
|
VISUAL
wHash
|
ff1820000e7e7e7e |
|
VISUAL
colorHash
|
01000000030 |
|
VISUAL
cropResistant
|
0041516363490002,8494c0f4a00a1e88,c0e6d2c0e2e0c1e5,2e302ccecec64c80,91898dc4a0643633,73e0c4d09cccecdc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.