Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1518394788541847ECECE83C4AF7A5FC9A2AAE34F85522C16B7FD97414F42E24ED1E610 |
|
CONTENT
ssdeep
|
1536:haGM+okaj+8fgzFYkhfpWcM7KVxXhVq1tVq1TVq1nVq1WGHnq59erSwsf:hqX+8QFYBKXXhVq1tVq1TVq1nVq13nqf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e8c6983d35956738 |
|
VISUAL
aHash
|
d5f5f1e1c1c3cfcb |
|
VISUAL
dHash
|
2509cb070f133317 |
|
VISUAL
wHash
|
00f1f1e1c1c3cfcb |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
25a98b071f133217,dc627ebc387060c0,004015c8e8e812c8,2c0d4d054d692b29,8f8b8b858da1c142 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 139 techniques to evade detection by security scanners and make reverse engineering more difficult.