Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15773E89A68943026073340D394BB2B9AB779583FF52805D1B1B8C7E572E88F5317AF4B |
|
CONTENT
ssdeep
|
768:VyWu1nUWuPyojwqtM51vBzMRW/9MXcNwGzLjsQ6Z/uK8n+/L5Cb127p4qHcozDiL:tSQxYXTQ1ikTyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
869568fcb358275a |
|
VISUAL
aHash
|
ff7e3f3f3f1b1000 |
|
VISUAL
dHash
|
ecf0747e7cb7b1d9 |
|
VISUAL
wHash
|
7f3f3e3f1f130000 |
|
VISUAL
colorHash
|
07c08008000 |
|
VISUAL
cropResistant
|
ecf0747e7cb7b1d9,81f8aeb2caceecfe,fffffbfffbfed272,dece0e8ec6f9f8fd,c8d8dada5ec3d163,743c5f5c7c3f1f89 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 476 techniques to evade detection by security scanners and make reverse engineering more difficult.