Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T104736532D3531903907BD2D9B071478D2262868DCB174F79A7BE63B6F6CFCB52612298 |
|
CONTENT
ssdeep
|
1536:CVVe1lQ0eeZee9qhpzyseuek57rl4pTeM0eHxe4e1rOJA+oeeetdeRROsgHeQuDy:E557rl4pFqOP/zlfDmFbq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6696c31939a93cd |
|
VISUAL
aHash
|
00003c3c66667e3c |
|
VISUAL
dHash
|
8ae6e0dcd4ccc4ec |
|
VISUAL
wHash
|
c3003c3c66e77e3c |
|
VISUAL
colorHash
|
02000038000 |
|
VISUAL
cropResistant
|
8ae6e0dcd4ccc4ec,e08e83e13c268ef8,e08e83e13c268ef8,2999e4f1332e2b22,16b0696299697015,15736961b9497115,33b33329b4f4342e,192a67d5f0e9f161,9793931323271b3b,10304cb2b1696a68,10214db373694d49 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.