Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B53863291865C139097D2D9B1708B0E3381C785CB174B6563F957BE7ECECB6AE2129C |
|
CONTENT
ssdeep
|
1536:0UETzZN/S91B1ipYqXBv131D1fzl17191571Xq/phZYq0WyeeeewyeqeMeeeeHIR:RjipYq3lBfrZ/rc12xed8Qg683EDITIZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3cd363199c39661 |
|
VISUAL
aHash
|
20007a7a40464646 |
|
VISUAL
dHash
|
6b27e2d29a8a9c8c |
|
VISUAL
wHash
|
3030fe7ac2c6c6c7 |
|
VISUAL
colorHash
|
02200038000 |
|
VISUAL
cropResistant
|
6b27e2d29a8a9c8c,3c64c430e7f26464,db9792bb3b021696,c931193519970f13,d9d39a991913529a,7298585a342525a7,2764e7f7e3ca6823,d7693248cccc442c,9793d6c569a27171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.