Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E1A29670D0947F3B418382C6EBB5877A32E5934AD5120B9647FAC35E4BCAE87DE32449 |
|
CONTENT
ssdeep
|
384:QG0zw9nAnFBqHJsJ5dk4bO/grHVVAhbkpLO9qQXFSTIbUgk0VYFCu7:QG+6AFbc//gr1VGMLOZZclFd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
98476763cc536764 |
|
VISUAL
aHash
|
00c79f9bd9c183c7 |
|
VISUAL
dHash
|
4c2d30b2b29f1f34 |
|
VISUAL
wHash
|
0087dfdbd98183c7 |
|
VISUAL
colorHash
|
07406000040 |
|
VISUAL
cropResistant
|
b28c8cb28e86a7a6,4c2d30b2b29f1f34 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.