Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11523DB3098C47B6B59D392C5F310671BE3D58244E2BAC94EE2EAC71712C5E89C85BB68 |
|
CONTENT
ssdeep
|
768:qqfzbboGBWgHl2udWT+J/eLBINbmBl0++MWmzCh1SmlpZhf/TISkK2rz+Ha9xw:qAzgGB5rdWT+Jm6RGlf+MWmzEUmlpZhT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946b84b4ebc0b6cb |
|
VISUAL
aHash
|
ff00000006067e7e |
|
VISUAL
dHash
|
71f0d4d0ecacacec |
|
VISUAL
wHash
|
ff18007c06467e7e |
|
VISUAL
colorHash
|
02001000030 |
|
VISUAL
cropResistant
|
4001416363490002,9484c0f4b0881e1a,6c4e7e7a4a3e7b41,f131e4e6c6e4f8f8,4d8c8c89a181c0c7,b2d0c4d0ecacecec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.