Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E2541EB0520465EB1BD3FDD065A2BF4750B2C9EAE25F098DA6AC894C5FC5FE0C8D43A1 |
|
CONTENT
ssdeep
|
3072:NQ1Mw5vwY3wXt5NOJmtYQ4MtGJrcq4OeZmDrgqpP679OMgSaOlMgSaOlMgSaOlMG:76SSSD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec4f50b3b1460ead |
|
VISUAL
aHash
|
d0c030170704f0c1 |
|
VISUAL
dHash
|
8493636f8f6d8793 |
|
VISUAL
wHash
|
fec0301707e4f0db |
|
VISUAL
colorHash
|
000000401c0 |
|
VISUAL
cropResistant
|
0303cbcb4a53034b,9aaa2aa6a28988a6,52caaa7306959099,72f071786c6860e2,0954e068e8040041,c4e2e3d0a4a880a2,100c323232304a40,1005383232300640,420d323236060201,0113484868600240,4019646468740240,4122c0c8cc264001,4103e4ececac0204,2c646a3eccc9dae2,8493636f8f6d8793 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 343 techniques to evade detection by security scanners and make reverse engineering more difficult.