Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T123F2D967839812FF2E2706D06A0123EBB349D04DD3444BD5F6ACC1BAA7D999426F67C3 |
|
CONTENT
ssdeep
|
384:7n3OlEqyCMKIrxxm5YsA9mH5m2SOy78vO8w3JRkcKD4/dvEZygqy4PgvIld:7+JvaWYsA9mH5mJOhcJS4lLgCowH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f543566949595479 |
|
VISUAL
aHash
|
00ffffffc3dfc3ff |
|
VISUAL
dHash
|
8c08cccc33961696 |
|
VISUAL
wHash
|
00e7efe781c383c3 |
|
VISUAL
colorHash
|
06200038000 |
|
VISUAL
cropResistant
|
cccc8c0f33961686,0004909494800400,6163796961717907,556323333333334d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 932 techniques to evade detection by security scanners and make reverse engineering more difficult.