Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B18353B2E282A82751A3C1C16FB56F6BB3C5824CDAC30347D3FCD32969A6DA1FD11465 |
|
CONTENT
ssdeep
|
768:47qNlWAgAPOHCDEe/dT3JAdyfTojApxuCtj4KO2YFFaIa50RAlL8bzFlRYyomhz9:T02ObNTJh2SURjo7teUM8kzY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e79a989c9865653c |
|
VISUAL
aHash
|
ffe7e3e3e3e3e3e3 |
|
VISUAL
dHash
|
964d46464646464e |
|
VISUAL
wHash
|
c3e3e3e320202020 |
|
VISUAL
colorHash
|
06400048000 |
|
VISUAL
cropResistant
|
964d46464646464e,18185aaaaa8a1964,f1967a30b89cd455,57e0d4d4d4c44d4d,eda34555554fcce1,5353d6dadb79650f,7153d85979797371,c68fad0d2d2f1505,5850d931371f13eb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 139 techniques to evade detection by security scanners and make reverse engineering more difficult.