Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14623B87108C56F2B61E382CA53507A0BD3E18548E2768589F5EEC31727C4EC9DE6BF98 |
|
CONTENT
ssdeep
|
768:CNkdxdqBW4y262EsB8ZybjofZyPFu0UYms/EgeTpPafPok7USkgIr2F6:CiPqBX1eZyHoBiFuFYms/EgeTpPaXcgE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946bb896ebc8b4e0 |
|
VISUAL
aHash
|
ff000000363e5e46 |
|
VISUAL
dHash
|
31f0d4d0ececbcdc |
|
VISUAL
wHash
|
ff00000c767e7e6e |
|
VISUAL
colorHash
|
02000000038 |
|
VISUAL
cropResistant
|
0001412363c90006,d495d35233173574,84c4c0f4a01e5e88,dde1616136373393,64682a643024271a,b6f0f0f8ddc79373,f0f0d4c4ecacbcdc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.