Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC7364F380C512379A6297C53A647F5E7EC6404FCF418B9DAAF897CC4BC6D93A921029 |
|
CONTENT
ssdeep
|
1536:j1unkZ4IeboZtdre19cneurLgelMtxebIDeD/Derv+elPZZb8O2NW/S2rVrP:j1cUC8Zg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac269b98c6e996e1 |
|
VISUAL
aHash
|
ff838381c3dfd98b |
|
VISUAL
dHash
|
272727270733332b |
|
VISUAL
wHash
|
ff818181c3dfc989 |
|
VISUAL
colorHash
|
07209008000 |
|
VISUAL
cropResistant
|
272727270733332b,ac9f5bcbcf9fdade,e48b1366e767671f,272f0f2c0c2cac0e,354b37f3f6eed4e6,bdbcb1b17044a42c,90557572b3a133db,0060696940140000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1084 techniques to evade detection by security scanners and make reverse engineering more difficult.