Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18AF260309146763B02C393C4AB36AB5BB3C18286EB630B555BF9875E9FCFE91DC21524 |
|
CONTENT
ssdeep
|
768:tLs094YCQosx9tYbQL1aIhxEB8LBAAFfwZY0kp/Q0jaUf79xGlH+K0Pm:Bs094YCQosx9tYbQL15hxEBO3fwZY0kk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6e38c99d388a966 |
|
VISUAL
aHash
|
fff70307040f1787 |
|
VISUAL
dHash
|
22268fcd4c7b3736 |
|
VISUAL
wHash
|
fff74107040f1707 |
|
VISUAL
colorHash
|
06602000040 |
|
VISUAL
cropResistant
|
22268fcd4c7b3736,19c542f9e4b8ea8e,372d0d6d6d3633b8,3cbdcf9f4f637323,4fe7f371338aa6f4,ddf573343e9fc7cc,2e263723042d631f,3113339bdb3707cf,b4b2b4b431d3cfce,58630f3bef9fdfff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 81 techniques to evade detection by security scanners and make reverse engineering more difficult.