Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11653B7F18416243E005B43EDEE51FFA9A2E789D5D75201A232AC8B4C67C5E68D83F42F |
|
CONTENT
ssdeep
|
768:JQBeURRBbFOHPTbjrvdlXfrDDWaeyeG0anN+97n:AOHPTbjrvdlJeG0anN+97n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d6286f10e3ef1235 |
|
VISUAL
aHash
|
000020ff7e7efebe |
|
VISUAL
dHash
|
71105555d4d46a6a |
|
VISUAL
wHash
|
000020fd767efebe |
|
VISUAL
colorHash
|
32200000040 |
|
VISUAL
cropResistant
|
90d4e4e0e0e0c8e0,cded64f4d454d4c0,ccccc8ccec6c6c24,1888cdf0eca4ace4,99caece9c9d9d9c9,76383cf43930d3d3,81e0909be0b0b939,968ef3e2e6f2f2b3,8cccf6f4b4f4e4e4,71105555d4d46a6a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 145 techniques to evade detection by security scanners and make reverse engineering more difficult.