Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3236371A055B93B02BFE1C1767A937B32E9825DF60702A062FD837C47DAD90BE36641 |
|
CONTENT
ssdeep
|
384:mMJhls1Y+X5l6ulGYGkv+iGalm19d/JR0iDLnuuEs+LH4S7pe3VrMBvah7MHymWk:mhOG5l6uQpGdlUh0++B7IrOc7IlBJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3c73c388cc6c33b |
|
VISUAL
aHash
|
062c7c7c24640000 |
|
VISUAL
dHash
|
c4d8c8c048dccc22 |
|
VISUAL
wHash
|
2e6c7efc6e6e00c0 |
|
VISUAL
colorHash
|
38000000cc0 |
|
VISUAL
cropResistant
|
091a52308adc3032,c4d8c8c048dccc22 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3525 techniques to evade detection by security scanners and make reverse engineering more difficult.