Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CC336030A404ED3B01CB55D9A636436A62EA8385C6530688FAF9C3F95BEFC6DDE37144 |
|
CONTENT
ssdeep
|
1536:usIxJ49BUVSFzGFz4Fz39jrBSuTMH7wrzu:uDVozszqz39jrBSYMH7szu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c112ed1a65ae54eb |
|
VISUAL
aHash
|
000c0000000cfff3 |
|
VISUAL
dHash
|
d8f8cad8d8b00b03 |
|
VISUAL
wHash
|
003e3e2e0c08fffb |
|
VISUAL
colorHash
|
0e2000001c0 |
|
VISUAL
cropResistant
|
08004b0b0303820b,ccf8b8cadad8d0b8,0000041a32b232c8,0010081032b232c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 95 techniques to evade detection by security scanners and make reverse engineering more difficult.