Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T130E394317A41AC21449F42EFE227271E61D1C7CCC64261E8B5F1C3B467F5CA8FBA61A9 |
|
CONTENT
ssdeep
|
1536:chyE5tdJ0IPmmTgzSykTya6EP6ojBfzSl6xgIPmmmgzSyDT6Kat6NjBfzSmZv752:6tQgv0U+yhlD0CxSccI0dH77z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9c78d9296c1b86d |
|
VISUAL
aHash
|
7e79406070602091 |
|
VISUAL
dHash
|
e0f393c3e3d3d333 |
|
VISUAL
wHash
|
fff9787878700091 |
|
VISUAL
colorHash
|
07600608000 |
|
VISUAL
cropResistant
|
a98089c1c1c98089,4baca4d48a92e262,2a2aa4d4c5e61894,c0c080a6ae88b0c0,8292aaaaa2b24551,e0f393c3e3d3d333 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1116 techniques to evade detection by security scanners and make reverse engineering more difficult.