Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13C051AF0A35C11FC950F47ED8931687C336E30B7B9128478897CBAB46563668CE97CA6 |
|
CONTENT
ssdeep
|
3072:083ZNeLTpSnScVi1DVCqyTYUegDxc9UqbhsyLP2rJvPDxBSJvm7x:08CCS9yp2hsW4PDxUJvq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3c84d475c6431f3 |
|
VISUAL
aHash
|
007fefdf8f070000 |
|
VISUAL
dHash
|
e2d09c3f18cd4d78 |
|
VISUAL
wHash
|
007fefdfcf07c000 |
|
VISUAL
colorHash
|
06001000180 |
|
VISUAL
cropResistant
|
8080a28282a280a2,d09caf351a5ccd0d,2e28286e7f0f2341,636363634a490c59,919911d136d3f61c,cba75359ecb667e5,b333c2e2e20dd0d0,9caf3518dd8d6970 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 279 techniques to evade detection by security scanners and make reverse engineering more difficult.