Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F4B225F05146A53B45F792E65B31AFAFB3D09259C5C2170B93FE83A88BDAC44FD16802 |
|
CONTENT
ssdeep
|
384:Hp7MiEIRt+0kP5MqiQ+OmwfYI86X/+pdl/Q+ZB2NTTOIBTV+RYt4qwB38sDBOMUZ:HBLRKP5J+OmI85pc+wTT5VJ498tMU6vs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d379c3a68361c333 |
|
VISUAL
aHash
|
fcb898003c3c3c3c |
|
VISUAL
dHash
|
d0303030ccc4c4f0 |
|
VISUAL
wHash
|
fcb898183c3c3c7c |
|
VISUAL
colorHash
|
31000001c00 |
|
VISUAL
cropResistant
|
d0303030ccc4c4f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.