Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19FB33CB03664F5A72AB343F3609B6602B279452FD40F8C207354ECAA77ACC9B5167F85 |
|
CONTENT
ssdeep
|
3072:fVh5C0NCSwzqMHFTE2uAzWpcgTjzmN6UbtZ9S:VCSwzqMHFTE2uAzWpcg3qNbtZ9S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9313ecec2cd3da82 |
|
VISUAL
aHash
|
01000c0000ffffff |
|
VISUAL
dHash
|
3bcdd9d9df1a0c4c |
|
VISUAL
wHash
|
1f000c0400ffffff |
|
VISUAL
colorHash
|
030000001c0 |
|
VISUAL
cropResistant
|
00632b2b2b6300ff,24d6c4b175212223,794c4c4c4cc9490f,8acaeecacaced0c8,d9d9ffdf000d4c54,ffdfc9d9f9d9dfbf |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.