Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13F23C93108C55F2721D383C8A311AA5FE3D58509E27BCA5AF5EE871A46C4DD9C82FF98 |
|
CONTENT
ssdeep
|
768:lCRzSR++ifsglmKrBXrZjhqVCl58qsjFrQ/MZYDyfcJEIgpbuipZ7fKMVIACj5MZ:lCRzSR++oJwKrB7BlOvJrSQYAcJEIubb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946b89b6b8cfb0b0 |
|
VISUAL
aHash
|
ff00000006763e1e |
|
VISUAL
dHash
|
61f0f0c48ccce4d4 |
|
VISUAL
wHash
|
ff180800467e7e7e |
|
VISUAL
colorHash
|
02000000030 |
|
VISUAL
cropResistant
|
0021416363490002,84c4d0b4881e1c8c,c4c6e6aa8e8cce70,e6d2b0328e9a1a1d,70f0d0cc9cece4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.