Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T106932FD794A520260B3280D358BB2B6A72B9547EF03506D1E5BCC7FA23DCC913236E97 |
|
CONTENT
ssdeep
|
768:zyWuPcNwGyu/CW/usH198n+1QLZ5v5XMFiF/DfTzLoSLMRAX8Ue+JEka2fi/bEzs:OJ8UAG5yOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8818d653e9d656e3 |
|
VISUAL
aHash
|
7e1f1f0b0100ffff |
|
VISUAL
dHash
|
f0f1fdd3dbdc3947 |
|
VISUAL
wHash
|
7e0f0f030000ffff |
|
VISUAL
colorHash
|
07c00018000 |
|
VISUAL
cropResistant
|
fcf1fdfdf5d3cbdc,f3f331b9fcc6a6a7,a9a9986c25a9a9a9,a282cc4b134d82a2,38007d3f3f494040,fcf1fdfdd7d3cabc,05452bd8c42b5523 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 476 techniques to evade detection by security scanners and make reverse engineering more difficult.