Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D8614123445AA45F920A87C093E2BAA69467C50EDF704F81DAA84BC7E5C8FB1B07225D |
|
CONTENT
ssdeep
|
96:L/KmKJtWRviRG/7I7q20Sgz0gR1PzkWd6HASyTFKkC:LUqR6RG/s7n0Hz0gR1Pzrd6HASyET |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc6633999b339926 |
|
VISUAL
aHash
|
0018181818181800 |
|
VISUAL
dHash
|
0834b2b2b2b2320c |
|
VISUAL
wHash
|
8199999999999981 |
|
VISUAL
colorHash
|
38000018080 |
|
VISUAL
cropResistant
|
14209e9e9e966804,0834b2b2b2b2320c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.