Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F9040AB174072537119F93CAD962B71DA2C2938DCB431AE4E2F8435C97FAD80B9D626C |
|
CONTENT
ssdeep
|
1536:S74757zYel7aHln7poquOolkj7aqNNiEr287wI8+rNudVHdP/2aPfOHfzjqEb+6A:24BzYuCnXi+Wwkqxfo/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be95c361c3361c2e |
|
VISUAL
aHash
|
ffff9fffc38181fd |
|
VISUAL
dHash
|
432b332c03272f0d |
|
VISUAL
wHash
|
ff9f9f87818181c0 |
|
VISUAL
colorHash
|
06602000000 |
|
VISUAL
cropResistant
|
432b332c03272f0d,f4e6e67664a0c4ea,458294b292938c45,135090a4e6b25092,7c5ccc5acaec67e3,79ebe3c7e76bcfcd,e9c52032a69d1b38 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 824 techniques to evade detection by security scanners and make reverse engineering more difficult.