Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T140B14531A884C63712A3C9D0A370AB3F62D2919DCD331B57E7F947598BCAEA7DC02645 |
|
CONTENT
ssdeep
|
48:d8JpQzcbkXSAlujwgLq80NUtFaJW4YqWPYVWFYDVWqY3WWQY/WkY4WtYrWQYCZ4C:d3UpAj1oaJxNO8eyvUWzsdTUIxNKC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c334476c1b3dd313 |
|
VISUAL
aHash
|
003c2c081c7c383c |
|
VISUAL
dHash
|
60e9d9d8b8e84949 |
|
VISUAL
wHash
|
007c2c3c5e7e3c7c |
|
VISUAL
colorHash
|
00000000c00 |
|
VISUAL
cropResistant
|
353663a3a58e3e3f,32b2d4d469785634,6c6c5a5a6a668c9c,d2b333bbabb9bbb9,9ebaa2b8c8be929a,60e9d9d8b8e84949 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.