Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T162635532D3931912907BD2D8F072478D2252868DC7574F79A7BE63BAF9CFCB52612248 |
|
CONTENT
ssdeep
|
1536:dQfiqJQ0eeZeeV+hpzyseuek57rl4pTeM0eHxe4e1rOEA8oeeeLdeZwdsgHeQCF/:PV57rl4pFKdP/bDD2qQWq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
966dcde830939ab2 |
|
VISUAL
aHash
|
00003626067e3e3e |
|
VISUAL
dHash
|
0a664c5ccced4c6c |
|
VISUAL
wHash
|
83023e2606ffae3e |
|
VISUAL
colorHash
|
02000038000 |
|
VISUAL
cropResistant
|
0a664c5ccced4c6c,2999e4f1332e2b22,245a53580f31ba4c,03162c2e130c8e43,33b3332bb4f4342e,192a67d4f8e8f161,979393133327192b,e369cd9434ed7d2d,040c132c5a533032 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.