Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10AE3DAA0F16098BD416FD5E2F3727F59A2EBE302DACD07D6E3E94BA80592D50EC13446 |
|
CONTENT
ssdeep
|
1536:12VBctijM2BzGS1jv2e99oBE0Q813KLioWPLUYvJZI9KFt/04TqKXfibGZv8zOub:nMYrzUYvl04TqKX6GZvq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8444f513eb26dcc |
|
VISUAL
aHash
|
0000cfcfc7c7cfb1 |
|
VISUAL
dHash
|
f0233b1e9b9b9863 |
|
VISUAL
wHash
|
0000cfcfc7c7cfb1 |
|
VISUAL
colorHash
|
0e000000c00 |
|
VISUAL
cropResistant
|
fcc0d000800000fe,233f1c9b8b991923,5253d3d9d5e143c7,0cb233cc00686130,3c9cb83a3c30363b,0100000000000000,43caaaaaaaf503f8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.