Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T186F240B471A055F741C7DBF9B3A5AB2B71D9C39DC663CA40A3F8838A1BC7CA58E41610 |
|
CONTENT
ssdeep
|
192:7PaZ2T1AmCLtDD9lIQcb5uHbl9UcbYp/xko9rwLwTy9vLbCqKlrwXxGm5OmdX9Vq:z8o35Co9ly9vP1e8koOSXTfLZZRbAVf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b2731cc72667256 |
|
VISUAL
aHash
|
001824bd3c3c1f4f |
|
VISUAL
dHash
|
ce7368a97171b31d |
|
VISUAL
wHash
|
0019327d3c7c7d8f |
|
VISUAL
colorHash
|
06202018000 |
|
VISUAL
cropResistant
|
0000000000000000,736aab7171b1b31b,c2c2c2c261909060,415171414d694551,7e71666676667676,992c26332b0e0f0d,0083c220448c8c91,5661691999097153,19234e4f8e3366c4,49514d4969313171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 53 techniques to evade detection by security scanners and make reverse engineering more difficult.