Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F2A243765081B937474296C0A77B930BF35682D6DF924E05B3F4830D8ECBEEADC5612A |
|
CONTENT
ssdeep
|
384:G9UN644FInzrw9LVloOamBJEgiviDM75JkVVGbx:G9544FIzIRuOam7Egzqx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b516f75e5429152c |
|
VISUAL
aHash
|
ffe701000000efff |
|
VISUAL
dHash
|
0c8cbbf7e2aa0b0e |
|
VISUAL
wHash
|
ffe703000006e7ff |
|
VISUAL
colorHash
|
0fc02000000 |
|
VISUAL
cropResistant
|
c4320d0c9c9bbbb7,f8e0c0b2f0c08600,0009d0b2b2050000,d42b0b0b0b0f222a,0b4c34dcdc94340c,0c9dbbb7fae3a6da,69e9703034546c70,8d898b8961d18100,cc4c28e1f1b9e86d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.