Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DCC131D1C408DD3607128AD9F7FA671BE5A2C319DB01198453FC42EB9BDFC60CA26699 |
|
CONTENT
ssdeep
|
96:TkSHMH4zdaPfSThBEwvFHVeVXVHFq0ehXLz/GhHCrJ:Qe64zdaidE/kjhzGC1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
98ecf08fd3a5e0e0 |
|
VISUAL
aHash
|
ff1d1c3c3c1e1e0c |
|
VISUAL
dHash
|
79b1b0e969e0b0b8 |
|
VISUAL
wHash
|
ff1d1c1c3c1e1e0c |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
79b1b0e969e0b0b8,6969d496ae4d96f5,f1ccb28a8a96c4f1,2be3e7d6d6dfe365,018129230f074e58,9f6d61991c3e3791,c7c0461b09090ac0,bb373647653458c9,8484040416163e36 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.