Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1406365335496BA762277598A62243F9DF156B84AEF73F5C0A3B801CCB3E1F058422ED5 |
|
CONTENT
ssdeep
|
768:th5hphh2ZCY7O/f+pfLDpbnfoho9LMbiFX1hk1tb7w/RzRyiHoXwhOYyVjMvkadz:x2ZCY7UeocRi+d |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
856cd2e3a53cd293 |
|
VISUAL
aHash
|
7e303e133f3d3c3e |
|
VISUAL
dHash
|
d4746466cafb70f0 |
|
VISUAL
wHash
|
7e303c13333c3c3e |
|
VISUAL
colorHash
|
30600018000 |
|
VISUAL
cropResistant
|
ededb3b79d934b4b,c6d27271e386e67e,2cad6512ebe52698,3ae6e6f8f8ecd010,989ca4b4358d8f4b,5ad9d9992b2b3b9b,0000402cd4c8ece8,d4746466cafb70f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 21 techniques to evade detection by security scanners and make reverse engineering more difficult.