Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T182924171D281F87B019382D1F739A75EBBC6854AC8A34B065BF8838D9FC9D95EC0245A |
|
CONTENT
ssdeep
|
192:oMsgS0ZWEgFXzPn2aR4183lFRrJermBOXwbPBJVnBJUGrLyQrJUzp6iAMF4Sq1mK:o8SKWbC0v1F3eiLnyIe3F4un1CfR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93ce6db3122dc3c2 |
|
VISUAL
aHash
|
030d3e0e6eef0200 |
|
VISUAL
dHash
|
d739ececcc483ad4 |
|
VISUAL
wHash
|
0f8f7f2e6ecf0200 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
337c7686c4c4c2b3,3913c6e6f7e75959,a981a98989a981a9,f0f8f8f0f0f0f0f0,70c482a0a080c070,d739ececcc483ad4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 239 techniques to evade detection by security scanners and make reverse engineering more difficult.