Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B4E29732C0019D7B419A81E4B6302B8FAD8187CDCA570B4953FA935EBFC7DF99E5118A |
|
CONTENT
ssdeep
|
768:uay3bnocgkc6oloYokkm74G4s2z8JKHhj3WU5FwyfOR7m1Dvu4hvlYuq+rQ9AafS:uay3bnoct5oloYokkrVs2z8JKHd3WU5r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cfcf4430b03127b7 |
|
VISUAL
aHash
|
7c3cbcffff000000 |
|
VISUAL
dHash
|
f06161515561b271 |
|
VISUAL
wHash
|
7cbdbdfdff000000 |
|
VISUAL
colorHash
|
06240001200 |
|
VISUAL
cropResistant
|
f07070606c595b72,6a69e80713233507,aa4a2a3b3a226ae2,f06161515561b271,527a262626361606,0c153335973636bc,ac222b3b631f7ff3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 305 techniques to evade detection by security scanners and make reverse engineering more difficult.