Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T174B360327E479826205F328F921B330C61C1DEC9EB62F6E0A1B4911C57F4F55BAA2ED5 |
|
CONTENT
ssdeep
|
1536:5NfUbByqhyqWu9iooFeQFogEzpb2+CoQjlE9OY3n+lgYYEOTeolJi:P89BWFo6FForzpb2+CoEELeoS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c5e41330b0ee4f6e |
|
VISUAL
aHash
|
447af2ffc300000c |
|
VISUAL
dHash
|
88c2669696f4cc51 |
|
VISUAL
wHash
|
e47afaffd700002c |
|
VISUAL
colorHash
|
30400040001 |
|
VISUAL
cropResistant
|
71e1b2a969496c54,96bc3c9d1e84ada9,11c6e299d2c6f6b6,da8aa86b28ea5858,a0b0b8bcb8be9a70,88c2669696f4cc51 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 629 techniques to evade detection by security scanners and make reverse engineering more difficult.