Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E333BC30A451EC2702DB96C45276276A62E28309CA530789FBF987F95FEFC69DE33504 |
|
CONTENT
ssdeep
|
768:YsIx/jXUf7BiglAtvF8As6s6OycwoZK0St/dytMA9einn+o:YsIxU7cvXXKXV5nn+o |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95ebaaa04b3560ee |
|
VISUAL
aHash
|
ffffff0040420700 |
|
VISUAL
dHash
|
8640169a96969e72 |
|
VISUAL
wHash
|
ffffff00c0460700 |
|
VISUAL
colorHash
|
07203010000 |
|
VISUAL
cropResistant
|
8641569e92969e9e,6471e1a9a4e4e494,0282f393c3e2f2fb,80e0a4ac8db4b0a1,99994e26908a8e8c,00f4a8aaca329697,b3b1310d21000000,0000014141010101,969a92d6969e9e73,181d000c4c7c0487 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.