Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154D37D603604B97E167743DA70AA7503F23CA22AD41D4810B398D97A37FAD96E473FD8 |
|
CONTENT
ssdeep
|
3072:olhn4FbamJE+ZhkZ6NZ4NZPDZuXZUHZiiZpkZPC5o3XXIMubGvnaKctbC:olhn4Fba2Dh06T4TPFuJU5i+p0PC5o3v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c33c633ce334c359 |
|
VISUAL
aHash
|
003c7e7624000078 |
|
VISUAL
dHash
|
c4f0f4d4ccf0d0c8 |
|
VISUAL
wHash
|
027e7e7e3c3c007c |
|
VISUAL
colorHash
|
31c00080000 |
|
VISUAL
cropResistant
|
d8c8c9c9c9c9c9ec,d6e69aa6b2b292a6,c4f0f4d4ccf0d0c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 105 techniques to evade detection by security scanners and make reverse engineering more difficult.