Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B7234A726332B8B843CB92DEF7382E56B2D2998DE8C74550F5C8568D23C3C816597BB4 |
|
CONTENT
ssdeep
|
768:aud2PdRMd++EsZx8/G8JWRF4PDawJMIBuwkMIBmwZUcix+y9dQpUDF1E56ITmHD+:aukPfMM+EsZ/8J4OPDawJMIBuwkMIBmM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fbcb958c9c94c186 |
|
VISUAL
aHash
|
ff81e1818181c7c7 |
|
VISUAL
dHash
|
1b0b4d0b23330f0f |
|
VISUAL
wHash
|
ffc1e1818181e7c7 |
|
VISUAL
colorHash
|
164000000c0 |
|
VISUAL
cropResistant
|
1b0b4d0b23330f0f,9fce4a59d9b32325,326ae8bc3c929a99,b3b3496c5454a3a2,6c4c93b5b7724c4c,252f6c5cd4b0b012,948e9e9e9e9c9c12,4c67382b2b8a5555,cfa7a7e7a78f8f8f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.