Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T109E2D4F04093D87BA29292DD47793F6F26E1CA28CAC30E8646F8532E5FA7E51DE13511 |
|
CONTENT
ssdeep
|
192:ryQvf43B8z0KbgnrM831XUJid9dagNKOze911Ato58iOoV1Gb+i:D/z0KUr331XBd9daLce9YtAO01Gz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf9899e732262666 |
|
VISUAL
aHash
|
1818181030303030 |
|
VISUAL
dHash
|
b2b230b06969686c |
|
VISUAL
wHash
|
58783efc71313136 |
|
VISUAL
colorHash
|
38002000180 |
|
VISUAL
cropResistant
|
b2b230b06969686c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.