Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6D141E1C514ED3747128AC5EBB66F5BB7D1C358DB03088097F883AB9BCAC60CA2559D |
|
CONTENT
ssdeep
|
96:TkHom0zejSTejGebyt7bM2sb5zFi4lkXVHF0KX3z/GNUST5J:QHom0zeuaGeby1Yb5cfzYb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
98ffc102e6399c33 |
|
VISUAL
aHash
|
9fff9f8f0f1f0f1f |
|
VISUAL
dHash
|
3030303abdb51ab2 |
|
VISUAL
wHash
|
8f9f8f0b0f0f0f08 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
3030303abdb51ab2,41251bc9e4c91345,4f4f4f8f173e7e7e,8b81d9c7c7c8c999,c54746061e0b4f46 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.