Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18BD3F8B06241A3ED454B874DFE30B6A4514FE2C9EB6B958962BA837576CFCC3DD001AC |
|
CONTENT
ssdeep
|
1536:aEMXiDJSBU5jowFtTtl0CYtFWUfscUjjQhS2Bzgd2rGJ+4niMzdpCfI/jdI/jL4O:aEPDtxltTYjD4jd4ei5Dtx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8df06a4b319755ca |
|
VISUAL
aHash
|
40d0fe0f183a3f08 |
|
VISUAL
dHash
|
9aa1a29e51566b79 |
|
VISUAL
wHash
|
48d0fe5f183e3f08 |
|
VISUAL
colorHash
|
1bc00008040 |
|
VISUAL
cropResistant
|
9998bc344e9b969e,e4e6e664243c2cce,60e2ea64d6f5d8dc,9e96f0ccccf08e9e,4aa6e2e4f3f3f3f2,e4e068726066fa6a,64581eb88ea6aab2,915b73f97ee2f1d8,9aa1a29e51566b79 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.