Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19963A923D3B34916517AD1D8B1AB57152682438DD7070FA0A3EDA3BE7DCEC723A122D8 |
|
CONTENT
ssdeep
|
1536:AjeernZeeheA0eAGee9heKeAmeDeA6eceAKeAkMIQeFEAAHebtAAU4SVleeYAA9b:UUzOIXBJtPABJtPw2Jm4BJtPblJ+2J9i |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e96c4c3930cf92d6 |
|
VISUAL
aHash
|
c181fffbc3cbf9ef |
|
VISUAL
dHash
|
3313e3d29a9ad398 |
|
VISUAL
wHash
|
8181f96b4343e9cf |
|
VISUAL
colorHash
|
07200038000 |
|
VISUAL
cropResistant
|
3313e3d29a9ad398,d2d1a13069b4e9c7,47cdc9f62433db39,31998d1e5b591b4f,2bebc9f92d2d250d,cecbd858696b3121 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.