Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CF8385BA41847137173BA7CC6A1DAF0AB2EA944DCF43046462EDC3856BE2F50CE7964D |
|
CONTENT
ssdeep
|
768:cmvWq2QbsU1wHRoGvHE+13Kw+9yE8zWj88OBxEgkzFaS7sZbU1wTU1wAU1wLU1wJ:5WUGrHE8B+9yE8zWj88OzkzRsZ6j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b45bc3a44bb45b8 |
|
VISUAL
aHash
|
000c08240c00ff7e |
|
VISUAL
dHash
|
32d9d8c8c8593bd4 |
|
VISUAL
wHash
|
000c7c3e3e08ff7e |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
49552b3b383e1040,3659d8c8c8d85339,24d3ccd4d4c4d324 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 126 techniques to evade detection by security scanners and make reverse engineering more difficult.