Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T174E34D3032047A3A66B7479AB09A7217733E971ED40B8821F269D15A37E9CD9D533FC8 |
|
CONTENT
ssdeep
|
1536:/0Ud5JUHYTrlJMyEyXPvbpWpFo2h20VTgHd8tVPTMnEXCd0uq+wSRKF:/0Udo+rrwyXspMug98nKd0+w1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c343028494ff7f6c |
|
VISUAL
aHash
|
3f0000ffffffffff |
|
VISUAL
dHash
|
fcc9535080c00000 |
|
VISUAL
wHash
|
000000097f7fffff |
|
VISUAL
colorHash
|
07000600030 |
|
VISUAL
cropResistant
|
fcc9535080c00000,f0c0b2e0a0a2d4f0,0f71aa94980a2507,966bddb230194326,0f3361e8ec61330f,0f3361e9e961330f,8f61617117676371,697333168e4d0d4d,696173b294d4cccc,8f6161636361618f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.