Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3A3CE27422939264437C2C134BA5B3BD1A6998FFAE70A005EECC7F72BF9C90745A15D |
|
CONTENT
ssdeep
|
768:gF29litpR4nXF6YjOpSpFlTC6rrWxcsLUJP//n8:g09litpR4nXBKpSpFl26vscsgB//n8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9aaa5826d3157d4e |
|
VISUAL
aHash
|
1c717d7e7c001c9c |
|
VISUAL
dHash
|
f1e1e1cccc35f038 |
|
VISUAL
wHash
|
1c797d7e7c0018dc |
|
VISUAL
colorHash
|
0a0030000c0 |
|
VISUAL
cropResistant
|
ff5fbfeff8e0c18d,f0f2a276e686c787,840084e0606000c0,c200806060c000c0,8200a06060a00088,ac00a0a0a08000e4,6a6c6e5a5a5a5040,faf8f8f8fc7c1c0c,f1e1e1cccc35f038 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.