Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T123A2972250C53E5B10C362CDFB524B5BF3D48144FD26C2A492EAC72F6AC5C88E97B6D6 |
|
CONTENT
ssdeep
|
384:ZftUIsl3pT+PjCcjmdv/htjyosYgvRfZKz15Bqq24faGvy9S4lv:ZftUI+pT+PrkbWYg5fZKzf5NdK9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93667c6493653794 |
|
VISUAL
aHash
|
061c3e3e3e04001e |
|
VISUAL
dHash
|
c475f8c8d8d92338 |
|
VISUAL
wHash
|
063c3e3e7e0c3c1e |
|
VISUAL
colorHash
|
38000008006 |
|
VISUAL
cropResistant
|
c475f8c8d8d92338 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.