Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19CC373B508A07F3B1B7B9DC91584279EF593A38EC6530E11BFFC52D86B82E51E02921D |
|
CONTENT
ssdeep
|
1536:1c0yt4ULqRiJFGU223E/IPhZtqvfQsWvxvjUFIIMtR01lOH59zf:1c5Z4YiOHH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91693d2e90c16f9d |
|
VISUAL
aHash
|
0000087e7e3c7e7e |
|
VISUAL
dHash
|
d631d2d0f0e4d4d4 |
|
VISUAL
wHash
|
0200587e7e3c7e7e |
|
VISUAL
colorHash
|
06200010040 |
|
VISUAL
cropResistant
|
f0364f6f6555f0e8,c676b0282864edb1,b3b2a4b6b6a6b652,4c74353535354d6c,2d2c6379c9e4e5c5,7b696d8dc9892d55,68ab7a62a26daa92,96b7a596941a5a5a,a3696b6a6a6a6a89,b292b232b292b216,d631d2d0f0e4d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 29 techniques to evade detection by security scanners and make reverse engineering more difficult.