Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T188A3D8B1F16C0A3E419BCFE0757267292267E20BDE4A1759E7E883751AD7CE0EC13249 |
|
CONTENT
ssdeep
|
1536:Ewj0NGMzULmVpdYTyG+Sm9z8lObejy7Ieo83EJ1k40Qiq+hGRDYVo8Q3lsSaO:Ewj0NG8gm98r/ZnlsW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba8645e947b809be |
|
VISUAL
aHash
|
fbffcfcfcfc9c100 |
|
VISUAL
dHash
|
531c2e2b2b1b3b1b |
|
VISUAL
wHash
|
80ffcfcfcbc98100 |
|
VISUAL
colorHash
|
0e200030000 |
|
VISUAL
cropResistant
|
1696637303160055,cd3f2b2f2b1b3b3b,9292936593939292,555155d4d4553151,9d57b4b0aaa8a889,b488984e17d06b67,a7a5afcb79338c8d,c264531b297835e4,1b3b2b3d3d131573 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.