Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18B33C7E1C1D2B63710B3E0D27BAB5F2952F1918EC9DA090A86FC76F596CDCA0B42754C |
|
CONTENT
ssdeep
|
1536:PpLfgMWBaYgDLHPZIep/aSjSkScvi2vUxzwUWAnwR2vYt4L:PpLfgZ/gDLHPZIep/aSjSkScv4nwc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
df209721a75896cb |
|
VISUAL
aHash
|
0000fc00f890fcff |
|
VISUAL
dHash
|
483121e161297168 |
|
VISUAL
wHash
|
0000fc70fcd0fcff |
|
VISUAL
colorHash
|
31e00000000 |
|
VISUAL
cropResistant
|
cc8e9111734e090b,1c3c1c9c2c6c4a4e,79fecec696c6f63e,e4ecf4783a9cce9e,c638301258d9cb4f,d2d3d3d29292b2b2,a8cececc9c969686,5f3759090080b0b0,5050545851626434,c2c6c6e2e464f3e3,9dbc9e9ed65949a9,483121e161297168 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.