Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T190410F335141E6B9371207F0D62171ECC183474FDDA1ACCAE0C081DAC699DDA563256B |
|
CONTENT
ssdeep
|
48:7PVdfDhvV3GV+ax/qVJikxwVJnlVJrVJd1VJviAeUzeu531hDEf6:bV9hd3i+SugJd/DjvZ9r5llEf6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be4ac18b5a3e1f60 |
|
VISUAL
aHash
|
bdff838199bfdbff |
|
VISUAL
dHash
|
6902273533622b2a |
|
VISUAL
wHash
|
91ff8181819b81ff |
|
VISUAL
colorHash
|
07c000000c0 |
|
VISUAL
cropResistant
|
6902273533622b2a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.