Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T147C1E1107558411F1333EBC1DAD6AF1B63E7F30AD205842084BDD9BC5BE2ED9A45BC69 |
|
CONTENT
ssdeep
|
96:thd6kmu/j3mw+ESOQD3SOX/STgjxULS6zVB5g:Akmu/jY/ij0jxU26L2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3e92c96c3e9928c |
|
VISUAL
aHash
|
fde0e86c2e0e0105 |
|
VISUAL
dHash
|
494959494d6d676d |
|
VISUAL
wHash
|
ffe0e0edbd0f0101 |
|
VISUAL
colorHash
|
380020001c0 |
|
VISUAL
cropResistant
|
494959494d6d676d,c9c999c9cc2c666c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.