Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18603A530A1945E6340A342C8A2E2471FF1EAC684FC86025BF7FDC3AE57C5D58DC26AE5 |
|
CONTENT
ssdeep
|
768:2s4bRfttjxqUm8BaB7BiBAB0gBdBfBeB6BVm38T7zGFfFYnZ8LZxq5KTpVcQhPqx:2s4bRfttjxqUvBaB7BiBABvBdBfBeB6J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf9eb0346430c79e |
|
VISUAL
aHash
|
06383c3838300070 |
|
VISUAL
dHash
|
cc626162606230c4 |
|
VISUAL
wHash
|
7f3f3c3838389078 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
cc626162606230c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.