Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115739972E2931913906BD1C9B1714B0933918B89C7134F7577FD27BAF9CECB62622298 |
|
CONTENT
ssdeep
|
1536:leVO88fXIMeeeeOzeerawbepe4epeFepeyegH7ZeeuepeLeJeReExK6QyQQFr5cV:lqb8xNpLJUgJ3JLJSJzz/AmTnmk6l+Xb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c18e3b31cd963396 |
|
VISUAL
aHash
|
60107e7c78686848 |
|
VISUAL
dHash
|
a8a6e4f0d2dad8da |
|
VISUAL
wHash
|
70307e7e786a6c68 |
|
VISUAL
colorHash
|
02000030000 |
|
VISUAL
cropResistant
|
4a44e4e4b4b4b4b6,e4c430e7c2306465,274506516f4e5129,4a4a9492c64ad5d3,4a4a9492c64ad5d1,4a4a90964a4ad5d3,4a4a9492d44ad5d1,a8a6e4f0d2dad8da,69a1a6a6a4670505,69e8e6e6a4678585,d7693248cccc446c,206f6464a9a5a171,97c56931f1e1a0ac,b0beb899878e8c83,a968666666a46787 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.