Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D4374B13865693B414B92C6E667630EE2C282DACF531D81B3F4936DCBD2DA4FD602D1 |
|
CONTENT
ssdeep
|
384:T/K3Ti5KxomCSiCCxTrSQ1CIIw3cCSiCCxTrSQ1WjxJdqEdilGGTTXS0wVD36c7g:G3G5zIIIiujPwC4GqTXSnVD36FJK3pFO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aeadf1944c2b2731 |
|
VISUAL
aHash
|
ffff010103030700 |
|
VISUAL
dHash
|
267d6b63676f7f01 |
|
VISUAL
wHash
|
ffff01110f171f00 |
|
VISUAL
colorHash
|
010c0001400 |
|
VISUAL
cropResistant
|
267f6b63676f7f01,5c4c23736d2a2aaa,a28a6413536482b2,015636c6c6161606,ff6f63e3ffefe6ff,01010101c08001c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1072 techniques to evade detection by security scanners and make reverse engineering more difficult.