Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185B3A5BBC7956B3FA7D89BC0C7913A2DEF43006ADD50C85AC283CF0D55B6E629813649 |
|
CONTENT
ssdeep
|
1536:RAsaS4JD0OjM2FHHF5jiGDaeAQGo+hNgqmYEZ88dJKxUcGUXENqaOEbAENqa4E6:RAnQ11EbAB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e0f8a1b8a1a5b1f6 |
|
VISUAL
aHash
|
ff0080e340007367 |
|
VISUAL
dHash
|
9e3444cb89a3e6ce |
|
VISUAL
wHash
|
ff0092ff40c07367 |
|
VISUAL
colorHash
|
1a000008280 |
|
VISUAL
cropResistant
|
05240025213e6e63,6860f06068686061,96c6465a64e5cd75,4a4b93a2e8caca09,ddcf5d2c68e0c292,b1f3db585a7a7aff,9e3444cb89a3e6ce |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 936 techniques to evade detection by security scanners and make reverse engineering more difficult.