Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1477396BEB744393A004753C6E63E5319A2D5C28BF6D25594B7F8831D0BD5CB0EAB212E |
|
CONTENT
ssdeep
|
1536:tj3cDdxLcWEHM5jPWvvZmKIcvx4xSx7nxrdbW9QuSSnaTWeHe9HPFn/xElzQLWbJ:N35W5E+8pnB8Xq+O0jOH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3d42d3b9bd44645 |
|
VISUAL
aHash
|
fffff0de0c000101 |
|
VISUAL
dHash
|
1a25c43858c5cbc3 |
|
VISUAL
wHash
|
fff4fafe0e010101 |
|
VISUAL
colorHash
|
1a000040038 |
|
VISUAL
cropResistant
|
0038a7c4c43c3858,98e0b0096b676f46,631acbecec5cb8dd,42f6b2b632b6b6be,e7e7bbb2b0313151,8d9d8f2391f4f898,136e9c70e3c2c2f3,0000442b3a3c4100,3c0f330549a31efd,25c42858c8c5cb43,ecd1428c1b64848b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 399 techniques to evade detection by security scanners and make reverse engineering more difficult.