Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7F372717D236C32111F62DFA12B630D61C2D7CADA4317E552F8C2289AF6DA0BEB3654 |
|
CONTENT
ssdeep
|
1536:URom71lSd9ASQ1iSd9JN9euADfcVWgI6Ho4CyjS7/5VSRAJM:5IlN9euADfcV3ua |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ae7ed51a54c64594 |
|
VISUAL
aHash
|
000101010101ffff |
|
VISUAL
dHash
|
252b27a7a7f3c318 |
|
VISUAL
wHash
|
0001f111133bffff |
|
VISUAL
colorHash
|
0b203000000 |
|
VISUAL
cropResistant
|
f0e0e0e0f0f0f8f8,0d1dc99a97951b0b,b0e8ece0e0e0f0f0,a7a7b3c3e3d81242,252f2f27a7a7f3c3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 976 techniques to evade detection by security scanners and make reverse engineering more difficult.