Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FED20514B605182F1173BAC1B421DAEF72D1F32B4703485666EC8AE9FAD7CB4F0696E1 |
|
CONTENT
ssdeep
|
192:jQ4oWnWAwUipkncM28pDAlANm3SxST8KXUz9tIG6xST8HiXw7ZQC8evpLI+GweM:jQ7WnEs5b3V0a9tI30OZQAYweM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9534ebebcb921434 |
|
VISUAL
aHash
|
ff00000effffffff |
|
VISUAL
dHash
|
69d68c7800080000 |
|
VISUAL
wHash
|
01000000fffffffe |
|
VISUAL
colorHash
|
0e0000081c0 |
|
VISUAL
cropResistant
|
6161804215254a90,86bc1a0408000000,d4dece9694ecac98 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 277 techniques to evade detection by security scanners and make reverse engineering more difficult.