Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T193B464B9DBA8D67E0A77C2C4AA861B5673F88159F4DA011243FED3F51AE7C44F903068 |
|
CONTENT
ssdeep
|
1536:8+IIBWFDVlfmRWtvlHEKf42SzWIGUVv9JoO6ixd2KqxHcBIgnCvzUwPrSoe7iqrU:8SCDu9nozUOyQdomrlU/weA3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee44158749ec16f3 |
|
VISUAL
aHash
|
3087d391c1f7ef00 |
|
VISUAL
dHash
|
e20d3733032f0b4b |
|
VISUAL
wHash
|
3087d391e1f7ef00 |
|
VISUAL
colorHash
|
0b0000001c0 |
|
VISUAL
cropResistant
|
a18082e2e28280a1,1f3733230b2f2f0b,7973d4552d4b5b59,06969e15a7969d0c,9f5d6715536464a5,aaa9e6e6a19ad284,b4a5b23161c10a90,85a5a5b1cddceece,2f2f0b0b0b6b404b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 94 techniques to evade detection by security scanners and make reverse engineering more difficult.