Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T182E373321A19153B019756CBE178EB1BE3E2C24DCA5B158A43ECD3295FEFD40DD26A38 |
|
CONTENT
ssdeep
|
1536:QX1TQNi8dsn0A16tUfPOy99C+2e2eGeF8YwQ7e1eYe1gBe9ZN8e2UieyeCeGe2eg:PiQRCGpXahVhCT7ugQaOHrK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ddab942f331d229 |
|
VISUAL
aHash
|
ff3b3930303001ff |
|
VISUAL
dHash
|
b267b14066e1b3c6 |
|
VISUAL
wHash
|
ff3f1928303001ff |
|
VISUAL
colorHash
|
0ec01000000 |
|
VISUAL
cropResistant
|
06599999590608b3,83909292d091311a,b4b474397c0f9f77,0a261388d263391c,61c9cc9c9a9b4765,97d7d7574706000d,b763b14064e7b3d7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 168 techniques to evade detection by security scanners and make reverse engineering more difficult.