Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1950230E1D064AD360B5292C9B7B5BB2B77B1C284CF020A4853F4537F6BCEDA187215A9 |
|
CONTENT
ssdeep
|
96:TkDntzH0L4jbSTFKiEhwvFUeRXoHF0X0WX9X/i/STu1dDGAT43a:QDntzH0Lf8iEO6OXl61f8K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b339fc311918c6e6 |
|
VISUAL
aHash
|
0f0f0f0f0f0f0f0f |
|
VISUAL
dHash
|
1a5a5e1adada1a3a |
|
VISUAL
wHash
|
0f0f0f0f0f0f0f0f |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
b8d8f8a0a0a0a080,88898e9c91919c8e,c0c0d0c0c0c0c0c0,88898e9c91919c8e,988e8e8e8e8e8e8e,8e8e8e8e868e8ee2,fac389989089c3fa,f0cc3ef6c68e8ee2,f0cc83e0f81e9cf0,8e8e8e8e8e8ecee6,8c4d4d6c6c097666,a09c9e96969e9cb0,86c6a6b6b69a9c9c,48496d9ba4ec8e4a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.