Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C383773552441A3EA597CBE0F1B0773AA1AFC34ADA1F955CF2FC42A22BC2C55CD16294 |
|
CONTENT
ssdeep
|
768:DzvXVoEWy+Yy99uMtTy+veBGvS0sq5E7jE1E7DN6YwsVY8xSYGPJY5YSE7E6hggX:89hly+veBGvS3IMOE6hggAGISoUAWYz2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93663c3c4ce1b7c2 |
|
VISUAL
aHash
|
06046c6c3e0e6e4e |
|
VISUAL
dHash
|
94dcccc8ecdcdcd8 |
|
VISUAL
wHash
|
060c6e6e7e6e4e0e |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
94dcccc8ecdcdcd8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3846 techniques to evade detection by security scanners and make reverse engineering more difficult.