Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1817286B5A090AB3B41D3C2D6E62A133FB2C25299ED870B0193FD877A56CBED1DC15219 |
|
CONTENT
ssdeep
|
384:xMqmLgTHjG5ojd4nE8TOSKs7ZA9IIQY9y6LhDwzmrCVaN/FTMYTUqTw3TQqSJHh:iqmLgTHjG5ojd4nE8TOSKs7ZA9IItDwq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b838969c4f33433e |
|
VISUAL
aHash
|
9d8b81c99b9f8fe3 |
|
VISUAL
dHash
|
3b331b13333c3a17 |
|
VISUAL
wHash
|
858b81c98bdf8f83 |
|
VISUAL
colorHash
|
07608040000 |
|
VISUAL
cropResistant
|
3b331b13333c3a17 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.