Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T189A2B633F205E13242A3229DFA55A349A3655285EF06FA5275BDC78E17C6CB2CC2317A |
|
CONTENT
ssdeep
|
384:QE9jE6RUdrIIadaQLXmvwSYZ7WxPX4Vha+bABV82Vxzj/Shp:h9Q6RuIIad9mISYZ74PJTuc/Shp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c912e936ec8b86e9 |
|
VISUAL
aHash
|
ff0028000000fbfb |
|
VISUAL
dHash
|
2fd8d8c8cde43333 |
|
VISUAL
wHash
|
ff003c2c0010ffff |
|
VISUAL
colorHash
|
1b0000001c0 |
|
VISUAL
cropResistant
|
20462620280a0028,5c98575b191919d9,1313231313323313,e7d8d8c8c8cde5e7,b8d84aacccd09eda |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1170 techniques to evade detection by security scanners and make reverse engineering more difficult.