Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BAC32FF22647193FEF47C2C6F6696A8CF186932BC6518C45BBE28A57DF41E28FC14160 |
|
CONTENT
ssdeep
|
3072:ELq+YvMoyF2v8BvhUv1Fvylv6jvlXNPPpXOo5+OsNs8sNsnlm:zrb+h6H6I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
868ef9095c743d47 |
|
VISUAL
aHash
|
00ffff1430012086 |
|
VISUAL
dHash
|
e4edace464dbce24 |
|
VISUAL
wHash
|
03ffff34340360c6 |
|
VISUAL
colorHash
|
0f201018000 |
|
VISUAL
cropResistant
|
e7ede9edecacace4,8d0822224842d2e6,3e0e9e288ce65c5e,1a180e0f0e01f0fe,86a0b8e4733c4e73,fc929a1a9292fbb3,c0109acc101c004e,94d4c6efe7edc9ec,7a36061223696321,ecac64e0dbcbec14 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 141 techniques to evade detection by security scanners and make reverse engineering more difficult.