Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T145F1417591A199331277C1CA7FA1A31F73D5828CDB831A251AFDC3BC1BEEDAAE815101 |
|
CONTENT
ssdeep
|
192:k9DFbiUnhbLOjCETEbaeSLNETEbpe5vNETEb3esWNsE6vmAHmi8Pl3VgJWszaGXQ:ioUnhbLJDaeS5Dpe51D3es8shz8Pl3Vh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3666699cc336632 |
|
VISUAL
aHash
|
e7e7e7e7ffe7e7ff |
|
VISUAL
dHash
|
4d4d4d4c2a4c4d0c |
|
VISUAL
wHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07640010000 |
|
VISUAL
cropResistant
|
4d4d4d4c2a4c4d0c,2a77575645e5696b,f2e6717269e2e030 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.