Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D18528A0D24C617C445F13E686656FAC335F21DAF452053CAAECD66CAAD2EE4CD0BC2D |
|
CONTENT
ssdeep
|
6144:F7CS9yp2hsHqt8Ikk2YSSj2XgvDjGBnRxxOiuo34AUYDX:FGp+tziu0DX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8dc9e75e4d4b3260 |
|
VISUAL
aHash
|
38ff003c10043f03 |
|
VISUAL
dHash
|
f2e0ddf0a27cf0c7 |
|
VISUAL
wHash
|
38ff013c180e7f27 |
|
VISUAL
colorHash
|
0b200018080 |
|
VISUAL
cropResistant
|
8200828282828082,0000c01b17c000cc,3f3a4e4a48ccd0c3,d9d5553454445a92,fdcc494d541a2825,8ffee62cce0c8107,f9f9e8e8fcbcd0fe,42421cd2e2e2f28c,cdd0f0b20c78c35f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 168 techniques to evade detection by security scanners and make reverse engineering more difficult.