Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9636532D3931902907BD2D8B072478D2252868DC7574F79A7BE63FAF9CFCB52612258 |
|
CONTENT
ssdeep
|
1536:6e5fJQ0eeZee9ihpzyseuek57rl4pTeM0eHde4e1rS1tFAyoeeeLZfde50tsgHe7:it57rl4p1/NZRtP/+DIq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
926d6d6b3cb39212 |
|
VISUAL
aHash
|
00206e46067e6e7e |
|
VISUAL
dHash
|
924ecc8c8cccccec |
|
VISUAL
wHash
|
00205e6e0e7eee7e |
|
VISUAL
colorHash
|
03000030000 |
|
VISUAL
cropResistant
|
924ecc8c8cccccfc,1974767476486412,0918747476486c12,0918747476486c12,00113d313958a9a9,3136030106030402,1252949252cc8d8c,86947472589c2696,33b33329b4f4342e,192a67d5f0e9f161,8694747a589e3696,9793931333271b2b,e3e92c646cec2d2d,c4923064767a5c98 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.