Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14603623090A6A8BB0027E5D5D6647B1B30CA827EEE970B0122FD5BBD1BD3C90ED2951D |
|
CONTENT
ssdeep
|
768:zloZOZyCp2IkhEXXN21Doz0WQ6qmjLYa4tGtvX:GCp2VhaN21DoYWxZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
852f7a916bca6692 |
|
VISUAL
aHash
|
000302206a767e40 |
|
VISUAL
dHash
|
03966646d6d494a4 |
|
VISUAL
wHash
|
cb0323207a7e7f52 |
|
VISUAL
colorHash
|
02230000000 |
|
VISUAL
cropResistant
|
9090900a4ed69166,a652b63612a6a1ac,b66ec7d2aeb6a62e,0a3024b232322a10,004323232323c020,963e47d2d6d494a4,8e235161f0f87062,0e3b8d83a343023f,86e42c0f070e8107 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 230 techniques to evade detection by security scanners and make reverse engineering more difficult.