Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13F436220A801AC3F52CB8AD56172537AB2A58355CA134A85FAF4D3F99BDFC6DCB33144 |
|
CONTENT
ssdeep
|
1536:BsIx94N21VePP2UzjIjltv5Us0obMatx79F:B8P2Uevttx7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d143934ef8aa51c7 |
|
VISUAL
aHash
|
203848c0c000ffff |
|
VISUAL
dHash
|
e9f2da922420d71c |
|
VISUAL
wHash
|
3c3878c0c080ffff |
|
VISUAL
colorHash
|
06c00010000 |
|
VISUAL
cropResistant
|
f6e6e2a8a8282a66,e68e0e26ea41f2e3,f0dac68a9c0a1235,6cd8d8b9fcc18f9e,00181816169e9e1a,e9f2f29a93b42834,0e1e0e4f8f0f0f1f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 205 techniques to evade detection by security scanners and make reverse engineering more difficult.