Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1322364F180659537028AF2D0B636571F76C3C78BE5470BA2A6FC432C2ACADD2DE2651D |
|
CONTENT
ssdeep
|
768:ZlgMkvdq3FGMq6COFJQdC3gf6IgMkvdq3FGMq6COd2gh0FlVF8cTrJ/1MMiUeMDN:ZlgMkvdq3FGMq6COFJQdC3gfNgMkvdqU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a64679998666799 |
|
VISUAL
aHash
|
0038301c1c3c3c3c |
|
VISUAL
dHash
|
494060b5b1796961 |
|
VISUAL
wHash
|
243c3c1c1c3c7e7c |
|
VISUAL
colorHash
|
08006000000 |
|
VISUAL
cropResistant
|
e1e1a2e3cdc6c7c6,ccc5c3c39e8e8cd6,494060b5b1796961 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 62 techniques to evade detection by security scanners and make reverse engineering more difficult.