Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A5758451F710D877A0D75BD9B1212602A2D6FB43D6C786C8E2FAA3B493D3A337127498 |
|
CONTENT
ssdeep
|
12288:r4vpv/dd0KXpvS2D+zaDvqWOa8lGM77YjcHLq7k:rMpvz0mpvlDoaDvqWOa8lGM77YjMLq7k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb143461de9fe194 |
|
VISUAL
aHash
|
0000fdbdbdf9efd1 |
|
VISUAL
dHash
|
68706969694b0b23 |
|
VISUAL
wHash
|
0000fdbdbdf9e381 |
|
VISUAL
colorHash
|
17e00008000 |
|
VISUAL
cropResistant
|
696969696b0f2b13,0004696968022929,0f11710b77274f5b,332b0d5911133541,7161252d251d0d65,c6c6ce4766676799,5e42a4a532509913,6d69653919597971,6161616171617131 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 778 techniques to evade detection by security scanners and make reverse engineering more difficult.