Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DBB3A83DE314067C964B0BDCDBE16E15212C40CB573466ACE62B42B2F619CFE98772E6 |
|
CONTENT
ssdeep
|
768:1la8nsHIlKukYjuBG0pSplSq6kM//0w4JLGNu6uydk17cr0GI6n6cJwwhWg9cU:yHIlGG0w/Sq6km01LGNup6lFWTU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
da5626ed6d919930 |
|
VISUAL
aHash
|
c0e4c8f8f8fce5f7 |
|
VISUAL
dHash
|
840ca8b2b2318d05 |
|
VISUAL
wHash
|
c0e0c8f8d8fce5e1 |
|
VISUAL
colorHash
|
01030000080 |
|
VISUAL
cropResistant
|
9726a4b89998ce02,70c6adcd6b242567,367ba525b992ccf1,f4cd6ce084c0c064,0c0950526271990d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 493 techniques to evade detection by security scanners and make reverse engineering more difficult.