Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A23C57058C56F2B11D382C8A350BA1BD3D5854DE27BC656F9DAC31E4AC2998CC3AF9C |
|
CONTENT
ssdeep
|
768:IquinKfNbqJcUsBgtlt+IIwctld8Eh92fqSJpHLUuP+2j03oOv8DxQ/KrGNFWlSQ:IquingNbqJRsBmltnVcZ8Eh7SJpHLUul |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946b81b4ebe0b4e3 |
|
VISUAL
aHash
|
ff000000041e767e |
|
VISUAL
dHash
|
7170ccf0ecfccccc |
|
VISUAL
wHash
|
ff1800100e7e7e7e |
|
VISUAL
colorHash
|
01000000030 |
|
VISUAL
cropResistant
|
0021416363490002,8484c0f4b0881e1a,c3f1d8dc7e3e2fd7,ce8b4d51c844c4ce,71e0e4d0ecdccccc,3622634b49cd9d17 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.