Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AA23D93114C42B6B51C342C9A355EA4BE3D58148E27AC65AE1EAC73F17C2D89CC7AF6C |
|
CONTENT
ssdeep
|
768:xMfIq1OPGB4szJCGK393Psje2Fj8Eh9/BRwKmI6ak/3yylS03PW58mvX0ztS57e/:x6IqYPGB4szkGK39Psje68EhlwzI6v/Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946b87b4e986b0ce |
|
VISUAL
aHash
|
ff0000000006363e |
|
VISUAL
dHash
|
5370ecf0acacecec |
|
VISUAL
wHash
|
ff1020101e7e3e7e |
|
VISUAL
colorHash
|
02000000030 |
|
VISUAL
cropResistant
|
0001416363490002,8484c0f4b0881e1a,09b5b4b5b6b1b0b1,71c994b4b6b2b123,71d0ecf0acece4ec,8913130b331b0f3c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.