Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T176237122E3420A1351B785D4F033578E23A58A8DC7570774B6BE67BAE9CFCB67611388 |
|
CONTENT
ssdeep
|
1536:fzoee+eleeseezreelyee/aE5mMIeCTp57r64pTeSejGTWeeDceeeneek8kZteeQ:T57r64plRozLCXq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a6d386c65659a9a |
|
VISUAL
aHash
|
1c3c3c243c3c3c3c |
|
VISUAL
dHash
|
6969714569696969 |
|
VISUAL
wHash
|
3c3c3c3c3c3c3c3c |
|
VISUAL
colorHash
|
03000038000 |
|
VISUAL
cropResistant
|
6969714569696969,060686696969e9e5,0000140c3434b230,80808543a4a4a48c,000010083030b230,808084cba4a4ac8c,8c94945454dc5d11,0000140c3030b230,808084cbb4a4ac8c,008a140830303231,809285c3a4a4ac8c,0000140c3030b230,8080a543a4a4a48c,0000140c3030b230,808084cba4a4ac8c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.