Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15C33B73118C45B2B55D352C9D354EA5BE3E98440B23AC74EF1FB835A87C5E98C87BA8C |
|
CONTENT
ssdeep
|
1536:/dfuuBW4+z+eSNt5jPeLidHezx9J2FgX6:/P+N286 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946be8b6eaca9486 |
|
VISUAL
aHash
|
ff000000063e7e7e |
|
VISUAL
dHash
|
71f0c4d0ececacec |
|
VISUAL
wHash
|
ff003000367e7e7e |
|
VISUAL
colorHash
|
02000000038 |
|
VISUAL
cropResistant
|
0001416363890002,7971f0e8cdcddc92,84c4c0b4a00e1c88,cdafb4b838298d8f,87c1f1f9edef0f8f,979f8c89b9a5655c,3660c0c08483c7c7,73a3e36313913333,32d4d0ececececec,a686076766632322 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.