Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T113735CF0A640F82309B740E2B09FA589B3BF140FEA1D0960B65CCDDE72D646B517B6D9 |
|
CONTENT
ssdeep
|
768:kT0TQH7c5UxYm3/aSsJdTZkJIsNM/jypv8i4ZYHoqUVzc+b42NB2jIGrTnzq8QEP:+3/aSsJdTZkJIsq/jaVWqAzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3f33994943c3cc6 |
|
VISUAL
aHash
|
466828007e7e0000 |
|
VISUAL
dHash
|
9ecbc9dcc4d45433 |
|
VISUAL
wHash
|
cf786c647e7e2600 |
|
VISUAL
colorHash
|
302000080c0 |
|
VISUAL
cropResistant
|
66466768924d4db2,d217170e272b6b63,bc962e6fb4d4ccb5,f8cadbb333773e96,d6e9cc8cccc84a5a,9ecbc9dcc4d45433 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.