Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2043272D8623133212F25C6F17DAB5DB5D3E71EE68367C182E843286BD6C85B837528 |
|
CONTENT
ssdeep
|
3072:3czxzn2W+X7NLFjBvtRFNnf1JFn1zFNFXX5l/BpHdbbNXrHlfbRR6OW6tK6G53+S:3czxr2W2RR6OW6tK6G53+z7GXTTVkwBP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d4717534b17530f |
|
VISUAL
aHash
|
00ff07ffd1ffffff |
|
VISUAL
dHash
|
d8a6ee9597942870 |
|
VISUAL
wHash
|
007f00ffc1f71f18 |
|
VISUAL
colorHash
|
07203008000 |
|
VISUAL
cropResistant
|
8282c2d2d2828282,92e4ee9597a82d70,d0d9e8d8c01a8a1a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2725 techniques to evade detection by security scanners and make reverse engineering more difficult.