Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE8365347801686630EF46CFE273798E2284EBCAD95619D9C6F04724A9F7C61FED12D8 |
|
CONTENT
ssdeep
|
384:XW0c25HZH6XV/GTTZcZB7E75CzFeA4a7a3pGSa7a3pGba7a3pG0a7a3pGt1ca7aX:F6QWzFe4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bfc01d6237486d33 |
|
VISUAL
aHash
|
00ffdbe7a5818f87 |
|
VISUAL
dHash
|
4814334d4d2b3b39 |
|
VISUAL
wHash
|
00ffdbe5a5818f81 |
|
VISUAL
colorHash
|
07000030000 |
|
VISUAL
cropResistant
|
4814334d4d2b3979,00004040d0404040,990f0f66274f0f1f,c0c3e73c38988ccc,e0e0e50a170c3cf2,3c9ebeae66f0f8f8,17696969694d717d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 646 techniques to evade detection by security scanners and make reverse engineering more difficult.