Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EEB29E236489882313A1F2C995B5271FB182421FCD175E218BE1DFDF1AE5DE89D3E21E |
|
CONTENT
ssdeep
|
768:/H4eHpRqYBBA/CvKak+/GNigJsjMUzB4h5LQ:AeHp7SigJgB4DQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
952f6a1fe0b1851e |
|
VISUAL
aHash
|
00005a5a5a5a5a5a |
|
VISUAL
dHash
|
9261969696969696 |
|
VISUAL
wHash
|
00005a7e5e5e7e7e |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
a28c8c8e8ec89686,b28cce8e8c8caaaa,a290969696a09692,ba84c6869ea0b2b2,b2888c8c8aaaa2a2,8a888e8c8eaab2aa,b2888e8e8ca28c8a,b28c8c8c8ec092b2,a2809e969ea28696,a280ac8c8cac8e8a,a280a2a2a28e9e9e,aa80a2aaa08e8e96,9261969696969696 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 102 techniques to evade detection by security scanners and make reverse engineering more difficult.