Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T192D30F30D1C5AC3B41E386C9AB759F1FE1C8824ACE93051583E983D997F6D969EC87C8 |
|
CONTENT
ssdeep
|
3072:w8qbBPns9+fZ0B6XE+y+rY6jYsRvUjnYgLaqkU+chbOlZPlFYlNPluPljHV:w8qb6bOlZPlylNPluPlj1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
80816f767a99ae2d |
|
VISUAL
aHash
|
00767f7f00240001 |
|
VISUAL
dHash
|
94d4d6d489ed4a2b |
|
VISUAL
wHash
|
007f7f7f01ff8001 |
|
VISUAL
colorHash
|
00000007000 |
|
VISUAL
cropResistant
|
d515aad654a63755,ceecacac9c3829cd,d4d0e028fadaa337,1657d7b6b7a72c38,ccc4e469d0f6face,4574aa2a0a9a1065,9dcbd294b64cdcd8,94d4d6d489ed4a2b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 471 techniques to evade detection by security scanners and make reverse engineering more difficult.