Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T148932AA43A5DF9665AF34393109F1103B379562B640D4C20A350FCAE76BCC9BA067FDA |
|
CONTENT
ssdeep
|
1536:BcX6fboQoCo2h2wV9Q/oDtVPTMn56QY2uQ74+A8v:aXexMAQgDnAYU74E |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ebd6953de180a4a6 |
|
VISUAL
aHash
|
ff80fde9a18181e1 |
|
VISUAL
dHash
|
097969494357534b |
|
VISUAL
wHash
|
ff9af5e1a18181e0 |
|
VISUAL
colorHash
|
03000010180 |
|
VISUAL
cropResistant
|
097969494357534b,575b616d68521414,5c78b666c6c2de4e,08745242aaa93333,3933370657676373,d09393b3b29e595c,692babc9c49e3135,cd4ea044dce42c9b,b9bff4aa5b6c3d39,8c37566c6c71d79e,d45453736d4d5bd7,8414cccebeed0f0e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.