Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E0838632E3971903907BD1C9B171474923918B89C7134B7567FD27BAFACECB63622298 |
|
CONTENT
ssdeep
|
1536:/1AeHiZ3G7MeeeeOceraw5epevepeKepe4e7H7ZeeoepeseJeheexsNgNQQBMDvr:sbF0eKcoJUFJc0JiJ0JzmqAmTn3JV2b3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e126693c3b93cc96 |
|
VISUAL
aHash
|
e0707e46527a6868 |
|
VISUAL
dHash
|
8aa6e494a492dbd3 |
|
VISUAL
wHash
|
6230ffc202fbec68 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
8aa6e494a492dbd3,8280175763397141,0909656a5bc9cac5,34a62646662d3c2e,e631126a6dc5cdcd,3509c101410f1134,2109c101410f1034,ce4b5878696b3121,7911314c481d94c4,d7693248cccc446c,9686d0ccc69282e3,3509c14101410b34 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.