Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE23EA30A010AA2702C7E6D49732678B73E2C305DE63068ABBF0C32D5FDBE95DD66655 |
|
CONTENT
ssdeep
|
768:ey05AiO44CsAavAEFIavAqFjavACF2avAiFEMJFfbaJFxbNJFbbQJFh0baJFfbdj:ex5AiO44CsAavAEFIavAqFjavACF2av5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed82f8cbed423906 |
|
VISUAL
aHash
|
ffff0301200000c3 |
|
VISUAL
dHash
|
a3870f07c2030707 |
|
VISUAL
wHash
|
ffff8383730001c3 |
|
VISUAL
colorHash
|
06001000180 |
|
VISUAL
cropResistant
|
23a207070f0f07c3,223a5a8d0a8eaca5,4828a6e6c6341113,3de3f6fdf9f1c9e0,63130343514842c0,000018e4c4c41840,070f07c3420b070b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 76 techniques to evade detection by security scanners and make reverse engineering more difficult.