Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18551752BB20095792FE324A1786D67CDCA0A045EADB1C9DD71F081EC67FDA8E05321F5 |
|
CONTENT
ssdeep
|
48:ZgB3uOavKIIkxKxwkFcguElso0wX0GvmK+afVjW3VKH/1E+g3DZm:ZeSienigKTuK+CjW3VKH/Fg3DM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4c7c819cdc931c7 |
|
VISUAL
aHash
|
7be7e7c78787cfc3 |
|
VISUAL
dHash
|
f20e8e1e5e1e3616 |
|
VISUAL
wHash
|
7b0747030307ffc3 |
|
VISUAL
colorHash
|
07003000240 |
|
VISUAL
cropResistant
|
f20e8e1e5e1e3616 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.