Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E4A3D7AB9280911DB22788E7907F335997389C5FD5060FF0B6B8EAF5F24D8921137A53 |
|
CONTENT
ssdeep
|
1536:aeeerePe8ezezetere7ereZeaeg2e7efeNeye5eDegeLeF6eTexetede7ePeKeJA:TD9ds8oWA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
881cd650e1f716f6 |
|
VISUAL
aHash
|
1f0f0f0b0100ffff |
|
VISUAL
dHash
|
f8f3fdd3bbbc6323 |
|
VISUAL
wHash
|
1e1f0f030100ffff |
|
VISUAL
colorHash
|
07c00018000 |
|
VISUAL
cropResistant
|
f8f3fdfdd5d3ebbd,bcdcaa8c6654eae2,73e3e1f9fcfeff2f,ce4aca3959ca4ace,5803232323232322,fcf3fdfdd7d3bf9d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 478 techniques to evade detection by security scanners and make reverse engineering more difficult.