Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ADE264B2C0C4797B4B52C6C4D7263BEAE2D28186CF079909ABF5475D7B4ACC2DC6206D |
|
CONTENT
ssdeep
|
384:+1mEU7rMhAZIa+yeB9RK73wCWKGF1H1bdx9yCASBri87nZnlnWnhnAitWg0gJo:iEEAh3WKmDB1ZlWhAith0gJo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9545d51f9e5a9382 |
|
VISUAL
aHash
|
7e62301c070fe0ff |
|
VISUAL
dHash
|
d8cae675ff58815f |
|
VISUAL
wHash
|
7e62000f078fd0ff |
|
VISUAL
colorHash
|
12400008040 |
|
VISUAL
cropResistant
|
6a4ab1a724e5646a,4e2d29734a57766b,2d262929aedcc92d,524c904d73cc0cb3,d3d3d036469e1679,52b2724a2a325d53,d41975e7bf0c5f58,cd87cda5e5a9b13e,8325845818dfc74c,d4d886caf414ef8c,5878001a00c98325,aeaec16165634363 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.