Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11C836732D3971513906BD1D9B072874933528B49CB134BB977FD23BAFACECB52622198 |
|
CONTENT
ssdeep
|
1536:ZOHOzceZ2XeSHeehYPUgOq61eErxgC+be6keenCIVS9QCGxTu0/DXx8ZDRHG21ye:r21UPUgOq6l+Aecxeg4Rk222I222222I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
90c7c3283e3b8ecb |
|
VISUAL
aHash
|
7e7e7e0642004006 |
|
VISUAL
dHash
|
ccc0d08caeae8e8e |
|
VISUAL
wHash
|
fe7efe4642024646 |
|
VISUAL
colorHash
|
03200038000 |
|
VISUAL
cropResistant
|
ccc0d08caeae8e8e,99d2b2b0a9a0b2f2,044b36c8c834a393,c9cc31831bbb359b,04cb36c8c834a393,d6693248cccc442c,c8cc30431bbb37d9,2565477747596b21,04cb36c8c824a393,d9cd30431abb279a,0662787169cd8949,179797d64569a3d1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.