Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14C82B5A2D3042B3507A242D9EB2D27FB6667814CE7020FA467FC437C2BD7C55D527989 |
|
CONTENT
ssdeep
|
384:WZZnIbbt6VYMlNF1GQyW0q2/nIIcEhveLFJKfiseBhRiUpJ08fGYP8F:uZY5kdF1LyW0q2/nIIcEhGLFEasuOa0Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e26a9dd1819e93f0 |
|
VISUAL
aHash
|
ff0000006061ffff |
|
VISUAL
dHash
|
c3c3e5e5c7cb34b7 |
|
VISUAL
wHash
|
ff000000607dffff |
|
VISUAL
colorHash
|
030020001c0 |
|
VISUAL
cropResistant
|
c3c3e5e5c7cb34b7,2d4cdab6b45569a9,ab7464ab0b2bb6af,df2636d2562e2ded,d480a29e8ea280cc,c1c1e5e5e5c7c5f9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.