Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10A72357735841E3B21C386F1BB907F16A6E9C5AACE178289A3F583695AC7C98CF04351 |
|
CONTENT
ssdeep
|
384:jXOgt+maDu1149Az5dgStK+5KLi8ES4++T5FEGBEB54:jXOgt+maDu1149I5/tK+5S5GT5F9+54 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
926dedd2929292ea |
|
VISUAL
aHash
|
ff00040c2c0c0d0e |
|
VISUAL
dHash
|
6bf7e9edc9d9f9f9 |
|
VISUAL
wHash
|
ff01051d3d2d0f0f |
|
VISUAL
colorHash
|
01000030003 |
|
VISUAL
cropResistant
|
6bf7e9edc9d9f9f9,fcfcbde969636fbf,07f0a8d4f4dcdccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 52 techniques to evade detection by security scanners and make reverse engineering more difficult.