Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AA23D1B3C1C96BBB1742C9C08617B23DD78300DECE93A646D6E50AD9DC6DFA1C463689 |
|
CONTENT
ssdeep
|
768:74vqLix/CMWbz8wfV1vgllFql5d0X8uwy7nax4nXWqjQ:74vqLix/CMWbz8AV1vgllFql5d0X8uwV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a8478736703f911f |
|
VISUAL
aHash
|
023039c381999bfb |
|
VISUAL
dHash
|
8e636b3323a32bb3 |
|
VISUAL
wHash
|
02b139c181d99ffb |
|
VISUAL
colorHash
|
19400018000 |
|
VISUAL
cropResistant
|
636b3323232b6b93,90b0e1618cccce70,b2d2b490d0d84c0d,f45c86c6d8c091b2,1196b5c8e8a8e8f8,8e636b3323a32bb3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 630 techniques to evade detection by security scanners and make reverse engineering more difficult.