Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B738732E3971413906FD2C9B161475922528B49C7134FB567FD23BAFACECB6262329C |
|
CONTENT
ssdeep
|
1536:4riOItHYeeee2eeca/IeyeteyeQeyefeQH7Zeereyeqe8eieo8WmP2QQD6aX1oFj:Cbhfi2HlJaJNJaJtJnaCAmTnmkQD+XoD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c14e3e31cdd39631 |
|
VISUAL
aHash
|
40107c7a68686868 |
|
VISUAL
dHash
|
aaa6f4d0d2dadad2 |
|
VISUAL
wHash
|
70307e7a68eaea68 |
|
VISUAL
colorHash
|
02000030000 |
|
VISUAL
cropResistant
|
aaa6f4d0d2dadad2,32e4c430e7f26465,0921a52667646666,34362662b60d2494,340d17133332bcb2,9991e1c121879894,5c040402051d5959,d7693248cccc446c,9181e18121079894,1c000c02071d5959,385c791ca012e5f4,5c040402071d5959,97c46931f1e1a0ac,d0f486c6b2a2a2a2,1101e18141610710 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.