Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T139E52ADC67B047F4DEC893FAEF3148E83A1B64FBBA518A28C26C5E94685155CCC58CC6 |
|
CONTENT
ssdeep
|
3072:kPVtd36o9+vJDnYX8f9Zp7cYyt/yVsCNB2QLRPkRKLxJqgDQeCuITOTsPQDFm5jB:W7mYs9L/cyuMReE2v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee39c4921d88963f |
|
VISUAL
aHash
|
ffe3818181f5f1f1 |
|
VISUAL
dHash
|
14032b2b2ba9a323 |
|
VISUAL
wHash
|
bfc1818181f5f1f1 |
|
VISUAL
colorHash
|
00c00000000 |
|
VISUAL
cropResistant
|
14032b2b2ba9a323,ae8ab6b69a86babe,2d3672d126718b00,6c105695caab8ec7,2802686961120000,14032b2b2ba9a323,05de4dc8ac24a4e4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 508 techniques to evade detection by security scanners and make reverse engineering more difficult.