Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15023A63114C42B2B528382D9B351EB4FE2968148E27AD756F5EEC31E16C6E85CC3AF5C |
|
CONTENT
ssdeep
|
768:bKKfpuIT54THB8i1JrKqGabtRsIVA8Eh977F3wK9B8je5Rk03wl584cE/KsJeXDb:bKgpuLHB8i1JrpG2tRF+8EhnwuB8je5R |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946b94b4eb84b6ca |
|
VISUAL
aHash
|
ff00000000767e7e |
|
VISUAL
dHash
|
7370ccf08cac949c |
|
VISUAL
wHash
|
ff180010467e7e7e |
|
VISUAL
colorHash
|
02000000030 |
|
VISUAL
cropResistant
|
0021416363490002,8484c0f4b0881e1a,3131323a088dad2e,71e0c4f08cac949c,c98c0ececdcd4b4b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.