Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AE3393707445A92B32A7D1C6F2236E0F71C0C3CACA964789E9F8837999F2C71BD61758 |
|
CONTENT
ssdeep
|
384:Q3ICRTItdhQ/fERNECOVQrtCQKe8j8S89Ww8v8Ovm8pzhvzOABBwvvtvQVb4Tqq:ERTihKfuiCOmEVYP9WNka9b4TX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92126ded6ded18b0 |
|
VISUAL
aHash
|
ff0c0c04ffffff00 |
|
VISUAL
dHash
|
18d959d9e4dcc433 |
|
VISUAL
wHash
|
0f0c0c00ffffff00 |
|
VISUAL
colorHash
|
020000021c0 |
|
VISUAL
cropResistant
|
0000501a1a180000,d28fae9e9cae0d8c,d4c8f0c8d4d4aac0,e159d9d919595919,80514d7133753333 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 628 techniques to evade detection by security scanners and make reverse engineering more difficult.