Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1666360B14222497B8647C1C2EE656F4AE2C6C31BCB639C91F7F5874AEFC2D14EC4A610 |
|
CONTENT
ssdeep
|
768:G7mXGDtfgkKHYKUqGWIPGxVe2pfWSeMrrZsFu+ZkKDA20DZHweDnndYXPtv0soVV:G7mXGDt4mqGWIPnSlTpaC27y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d62469c36cb096be |
|
VISUAL
aHash
|
420086763c6eeecc |
|
VISUAL
dHash
|
92162cececc8983c |
|
VISUAL
wHash
|
420096767e6eeecc |
|
VISUAL
colorHash
|
31081002000 |
|
VISUAL
cropResistant
|
916a6a7a5e766887,d098d89094bc9898,bad8da4a4a6b4b6a,31e8aae8e9716949,dbb3da44b6b2feec,fac0d8d0d0d0c0c0,92162cececc8983c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 163 techniques to evade detection by security scanners and make reverse engineering more difficult.