Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CBE29772C0019D6B419A81E4B6312BCFAD8187CDCA570B0953FA935EBFC7CF99E5118A |
|
CONTENT
ssdeep
|
768:uay3bnocgkc6o9oYokkm74G4s2z8JKHhpgUBxJyNO0D51Dvu4hvlYuq+rQ9AaE1S:uay3bnoctxo9oYokkrVs2z8JKHbgUBxZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cfcf4430b07127a7 |
|
VISUAL
aHash
|
7c3c3cffff000000 |
|
VISUAL
dHash
|
f06161515561b271 |
|
VISUAL
wHash
|
7e3cbdffff000000 |
|
VISUAL
colorHash
|
06240001200 |
|
VISUAL
cropResistant
|
f07070606c595b72,cccc9a8a8692aaf0,aa4a2a3b3a226ae2,f06161515561b271,527a262626361606,0c153335973636bc,ac222b3b631f7ff3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 305 techniques to evade detection by security scanners and make reverse engineering more difficult.