Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B6A185B4219616BF22878AE076A1BB5EF48BD30ECB33D108F1FB939527EAC51CC94154 |
|
CONTENT
ssdeep
|
48:L4UTNmTNMzydvCdbiMY9qyzygxjokgGEYYHCMFSNcff0eKbPBU84JGkzmjg0j+of:AQOMY9qyGAMCM9EOVzOCo0cho4UC4Kgo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a6c6991fd0333bd0 |
|
VISUAL
aHash
|
fff7e7e7f70181c3 |
|
VISUAL
dHash
|
20444d4d066f1716 |
|
VISUAL
wHash
|
ffc3c3c7e70100c3 |
|
VISUAL
colorHash
|
070000102c0 |
|
VISUAL
cropResistant
|
20444d4d066f1716,404125154b4b4b4b,502011545545338e,8f0f7d5a31646917,33f5e7b7f1c4f533,73b59c8c6cacb593,9f6361717161639f,4930b535b5b4b448,793959894e656271,d3d3c5c5c5c5ec2c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 203 techniques to evade detection by security scanners and make reverse engineering more difficult.