Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FFE4ED64E6E4143EC5214BD9E3BDB9DF7052700BDF2C11409BD02235592AAB6FF2E3A9 |
|
CONTENT
ssdeep
|
1536:vwemHDXqFoESVuAuK0161BxhzE9F3k07NZ92lZBS12VfV6Vtw/F7Z8X9hhCRyJE4:vw1HDXqFork3k2MkURrwrghGeY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
876d5a393a313a74 |
|
VISUAL
aHash
|
0030323f3f1f1e0c |
|
VISUAL
dHash
|
64e6e6f8fcf8f8f9 |
|
VISUAL
wHash
|
0030333f3f3f1e1d |
|
VISUAL
colorHash
|
18000008380 |
|
VISUAL
cropResistant
|
da9e9e942e2d7d27,bab2c2b230c29282,a000c0c0c080c2b0,a2d2c2f034c2c2a2,a2c1c2f034c0d1a2,64e6e6f8fcf8f8f9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36647 techniques to evade detection by security scanners and make reverse engineering more difficult.