Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112D2953BD6482233009B52D07BA67AE6F3A28258DB37555036ECA35C03CAD55CFBB758 |
|
CONTENT
ssdeep
|
384:y22WVVTUOW5gg6nMSiWIspUaGSs507Ks/G7pEgYS2Mrkd7pEK:y22WV9VcggcMW9p1lFKsuygH2MSyK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92726fdd1acd3844 |
|
VISUAL
aHash
|
000c470e0cfefe07 |
|
VISUAL
dHash
|
49d98d589c8c666d |
|
VISUAL
wHash
|
000d4f0e0efffe07 |
|
VISUAL
colorHash
|
110000100c0 |
|
VISUAL
cropResistant
|
c9cdacdc9cac726c,4f3ef9cf3ffffff8,98b273e4c89b9bb3,3129544663624944,49d98d589c8c666d,0e6969cceccc4c33 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9758 techniques to evade detection by security scanners and make reverse engineering more difficult.