Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE34BA26D33C237C0D8947F4DE2970F020AEA2DDA2D8917CB6648B60B7475F5E8A5ED4 |
|
CONTENT
ssdeep
|
3072:wzmHg9IqHGQ5Hg4jdgXFUBqwOhyGnGCOrnp7S0OuWmn8QESLduRChquTDxtTmFRx:0WeGQqu+AMNI4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f82187438e4a5f5d |
|
VISUAL
aHash
|
41c3c0c1c0c0e0ff |
|
VISUAL
dHash
|
979f1a91939a8534 |
|
VISUAL
wHash
|
c1c7c3c1c1c0f0ff |
|
VISUAL
colorHash
|
03000400010 |
|
VISUAL
cropResistant
|
979e1b9193988534,8e9eb270d8903604,cdd4d52b282a8292,e0e0e0e0e0e0f038,000c2c52525a2c0c,0f3ea6ebcb44350a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 627 techniques to evade detection by security scanners and make reverse engineering more difficult.