Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C093A732D212240391A7D5C8F1624B4A73528759CA134BB5B7F827BAFECECB63751398 |
|
CONTENT
ssdeep
|
1536:hcj9Up9Ug9UM9U99UU5QYSe2SePEXeRj2KPUgOd61eOtpQj0EUeeQBSlkQ6CKJ8+:ve0EaPUgOd6W5qT63xk222I2222222pb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f88f2738d0c3cb83 |
|
VISUAL
aHash
|
c383ffc7c3c1c1c1 |
|
VISUAL
dHash
|
1626639f9f8f8f8f |
|
VISUAL
wHash
|
c383ffc7c1c1c1c1 |
|
VISUAL
colorHash
|
06200038000 |
|
VISUAL
cropResistant
|
1626639f9f8f8f8f,9192b2b0a9a022b2,9040c0cc2463c7c5,d76168cc4d2d8641,272b3b2b2b3327c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.