Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17AD4F9FD932C616C34834B8CFF26B575635FE4BAF961465089ADCB7824C38A5F5238A0 |
|
CONTENT
ssdeep
|
12288:F9G03agMaQvY06aY2ZCMhmNgMk+Sl9FcIkEHGQz7ibTOaNlSE7FPIgEjRrK:F80TMq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ebe39ec24d963062 |
|
VISUAL
aHash
|
ffc3c7e1e1e19f81 |
|
VISUAL
dHash
|
710f0d0313132933 |
|
VISUAL
wHash
|
ffc1c3e1e1c18d81 |
|
VISUAL
colorHash
|
06206008000 |
|
VISUAL
cropResistant
|
710f0d0313132933,23250b1e1e0b030f,9beece261abcb882,ffffffdfffafbef9,565656d6939bc9c5,d4d4dcfcfccdcd8f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 230 techniques to evade detection by security scanners and make reverse engineering more difficult.