Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14EA2153194C0693A127786C9A7F9932BB3E2F2C1DD474A0566F8970A8FC7F81FD52641 |
|
CONTENT
ssdeep
|
384:91g1V1tJBp8XBSMLpvXBKgrXqQd1Qim4N52rs6oXhK1B/MD:QBp4GoxQMD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f9467f1d160e1d2 |
|
VISUAL
aHash
|
ff1f1f1fff030301 |
|
VISUAL
dHash
|
7873f1f361276b43 |
|
VISUAL
wHash
|
fe1f1f1dff010101 |
|
VISUAL
colorHash
|
06200008080 |
|
VISUAL
cropResistant
|
7873f1f361276b43,70e6e4e8e24accd8,9d786968787898a1,38594b5d5943474d,696b6978787078f8,0a3e6e3c3c1c5959,033e8d8301031303,89899d9d0d3f3f3b,3674747373737474,d5d584941494a6b6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.