Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE73A832E2411503A06798C4F1638B5E7356875ACA070B7576FC6B6AEACFCF47762388 |
|
CONTENT
ssdeep
|
1536:hZwayGDh/aisByEUR2ClV4UBLfod9VmMSeVXkhSu8Njt2rxk222I2222222xUOUp:haa/LOv6Hrdxk222I2222222GT8MX9i4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c126cf329391e7ac |
|
VISUAL
aHash
|
60007a4e44607c7e |
|
VISUAL
dHash
|
caa2e2988a8af2fa |
|
VISUAL
wHash
|
f2007a4e4e427e7e |
|
VISUAL
colorHash
|
03200038000 |
|
VISUAL
cropResistant
|
caa2e2988a8af2fa,099964f131272b2b,044b36c8c834a393,c9cc31831bbb359b,04cb36c8c834a393,4b4b3198d8d08c4d,c8cc30431bbb37d9,3e92db4bd31a2b2b,04cb36c8c824a393,272b3b2b2b3313cc,d9cd30431abb279a,0100010b02360ac9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.