Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF834BF4A480FE1311B340D3B0AB9606B37E450BA81D4860F69CDBDA72F586661B77E5 |
|
CONTENT
ssdeep
|
768:MT0TQH7YFanUxQt9UK2eQUMMlIlcogGaiiZkIEM26yyLGVJBr3ffY8R9FfDbbCIC:e9zpTg9XOK7qlURtywWGvzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d339c4346d96f522 |
|
VISUAL
aHash
|
023c3c08003e7cfc |
|
VISUAL
dHash
|
9cd9c8f8c4e4ecc0 |
|
VISUAL
wHash
|
063c3c18207e7efe |
|
VISUAL
colorHash
|
30400010040 |
|
VISUAL
cropResistant
|
387cec9c98fd3d1d,00000c0c0c080000,e80c56862baba3c2,2c9693b1b593b992,1636687872f8f0b8,ecdcdedc4ccccef0,9cd9c8f8c4e4ecc0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.