Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8240A9456402427473B8BC920DB37FAB1A5070DCE8E4444DBFC67AA93FBC61B59FA48 |
|
CONTENT
ssdeep
|
1536:R+Vrdruye2eOedeTceXefeXeieqh/Ae/CQeoexkemehbeCeAe+edPeEe8eieveRV:R+QtQu5AlKdT4rX2wd9W/guGO+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b616e9e98d28c1e9 |
|
VISUAL
aHash
|
ff040404ffff81ff |
|
VISUAL
dHash
|
23cccccc0c2b2b2b |
|
VISUAL
wHash
|
ff000000f7ff81fb |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
03236068600c2cc0,e2f28031718e9eba,f0cc869387acccf0,4d0e002b2b2b2f2b,2ccccccccccccc2c,8251c6a6c6ce6102,8261969696966281,8259a6a6de966184 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 97 techniques to evade detection by security scanners and make reverse engineering more difficult.