Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12A13B524920971520BBA4BF4E97D420762875C9FF9B3B5A05E39F7E634C3FA0AD5E104 |
|
CONTENT
ssdeep
|
768:vPt7LHo7qZjispgNmzUoIE+GnIWnIjiD99jifsdaib983k96VkahHxPWDTKTne0w:vPtnHo7qZjispgNmzUoIE+GnIWnIjiD1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3c3c8ce8c38c33e |
|
VISUAL
aHash
|
ffe7c78787c7c7cf |
|
VISUAL
dHash
|
a05d1d1d2d0d3d1a |
|
VISUAL
wHash
|
7f07078787878383 |
|
VISUAL
colorHash
|
06200048000 |
|
VISUAL
cropResistant
|
a05d1d1d2d0d3d1a,923e3e1cce6cb2c8,1d372d5d019bdfc3,1f2d21352119312c,05070d0781d14d47 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 82 techniques to evade detection by security scanners and make reverse engineering more difficult.