Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F8737632E3830807A06FD6D4B0215B5912958A49C7570FB9767E32B6FACFDF56623388 |
|
CONTENT
ssdeep
|
1536:58vye5Cp858JZjSG84jm6T2io5LHh4SWm1zEV9NqzhFaBbJyN6cscrCZpEzk17YM:58PS8587SG/2iYH0Ou/q1mbJcscuZpEC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
926ccd3293cb346d |
|
VISUAL
aHash
|
0010307e04047c7c |
|
VISUAL
dHash
|
aba7a3f98d8dd9d1 |
|
VISUAL
wHash
|
4130707f47477c7c |
|
VISUAL
colorHash
|
03000038000 |
|
VISUAL
cropResistant
|
2448501764e45452,dcce89c9cd8a8bcc,f2d35b2c3470e5e8,ddcda8a8acaca8cd,dcce89c9cd8a8bcc,60da2c2e2eecd8da,dcce89c9cd8a8bcc,dcce89c9cd8a8bcc,dcce89c9cd8a8bcc,dcce89c9cd8a8bcc,aba7a3f98d8dd9d1,d0c6c0d8cab4aab2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.