Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A0C374B508A47F3B5B7B9EC91584179EF5D3A38EC5530E15BFFC42D96B82E01A02A20D |
|
CONTENT
ssdeep
|
768:fGIeHIrqyE06yEfM8ABJiILzZVka91aia0BvmJ0aBStj9pxAgJTmcS97sdZhf:d1rqyE06yEfM8SLzrka9aBStj6gJI9wf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91782d2ed0916f9b |
|
VISUAL
aHash
|
0000387e7e3c7e7e |
|
VISUAL
dHash
|
d635d0d0f0ecd4d4 |
|
VISUAL
wHash
|
0200387e7e3c7e7e |
|
VISUAL
colorHash
|
06200010040 |
|
VISUAL
cropResistant
|
f0364f6f6555f0e8,9392b3b2b2b6b6b6,e3e3e3d336386cb5,b3b2a4b6b6a6b652,4c74353535354d6c,dab29ab6b232b5b5,3b296d8dc9892d57,53555a4469c34301,cc86c68997d60c0e,a3aaea2aaaaa6a49,6d6d266c25662692,8ab5a4b6b6aaa9cb,d635d0d0f0ecd4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 29 techniques to evade detection by security scanners and make reverse engineering more difficult.