Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17B73E932D3451103A05B98C8F1269B4E73528759CA138FB576FC17B9EACECF52B62398 |
|
CONTENT
ssdeep
|
1536:vAVwRqlnHSIlf2oX2TsdVZ6zf692oRChqIzxWLQfLkGyvPrxk222I2222222AtQR:DUHSIllGTY92XW0fXQxk222I2222222n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c12ecf329393c6ac |
|
VISUAL
aHash
|
60007a6e40407e7c |
|
VISUAL
dHash
|
caa6e2d88a8af2fa |
|
VISUAL
wHash
|
72407a7e42427e7e |
|
VISUAL
colorHash
|
03200038000 |
|
VISUAL
cropResistant
|
caa6e2d88a8af2fa,04c836fc15152d2b,044b36c8c834a393,c9cc31831bbb359b,04cb36c8c834a393,4b4b7198d8d08c4d,c8cc30431bbb37d9,3692db4bd21a2b2b,2565477747496b21,04cb36c8c824a393,d9cd30431abb279a,9797e368d0e09080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.