Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F7146371F1304627189B97F8816537DBF4C0F75ACB9352D882F493A96ACACB6FE06064 |
|
CONTENT
ssdeep
|
3072:HLw/zvp+PFekDDrnaIBFO+JDQknRJ6ovzR6yVX5cmoa9sJ/r:HXsJ/r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0d8a76e3d334d45 |
|
VISUAL
aHash
|
ffff7ccf50000000 |
|
VISUAL
dHash
|
0fc1c0b897e4cac2 |
|
VISUAL
wHash
|
ffff7c8ff0300000 |
|
VISUAL
colorHash
|
06e01000000 |
|
VISUAL
cropResistant
|
08c1c0d8b89796e0,1050d0d0503a92ba,aaa222ece4666e6e,000028b2b20c0000,c0d0b897a6ecca42,27b3b8383888ea77,43cdb4f3c3cdd3d3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 285 techniques to evade detection by security scanners and make reverse engineering more difficult.