Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T171B3D610E55CB83F04A702D8B131476D72F94306D2630558F6EAD7A8AB8FC2EE53B798 |
|
CONTENT
ssdeep
|
1536:UvoVf7GARwVmDOAkdEFscF1Frq5eP1sIxEx79grFYFP/VSXlPsAkw:UmfrRwVmKAkdEFsc5+5eP1C7S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cfd436b0f203ac4e |
|
VISUAL
aHash
|
84f83878f8f030b0 |
|
VISUAL
dHash
|
4c6163c3e0e2e129 |
|
VISUAL
wHash
|
a4f8f878f8f038b0 |
|
VISUAL
colorHash
|
13007000040 |
|
VISUAL
cropResistant
|
e3e1cbdb9b8ae9ed,4a5a528a0a5aca63,64740b8abaa6a9e5,4c6163c3e0e2e129 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23143 techniques to evade detection by security scanners and make reverse engineering more difficult.