Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F538471A5875A3F4A87D2D1AB356B9AB2C6C34BC7520D0477F1830B8F82E54EE1E670 |
|
CONTENT
ssdeep
|
768:1TnZ7viJBJBse+fZHzaDbcduhPty0gKIBKen8QT/rifyzJZl2V1Bp2XHiALaaJCu:1+MJogg3YmtU1F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d228a5d7f8c2d6a8 |
|
VISUAL
aHash
|
ff000000003cffff |
|
VISUAL
dHash
|
2bb2f16921c46432 |
|
VISUAL
wHash
|
ff001800007effff |
|
VISUAL
colorHash
|
0fc00000080 |
|
VISUAL
cropResistant
|
0104414b4b6100b7,9294e9c3d5d5b0b5,b67169ce961d5542,c4c4e427272b9ab2,bab3f16d69236cc4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 141 techniques to evade detection by security scanners and make reverse engineering more difficult.