Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10C7288E36A8F36278247017DBA8BB6CCE622845C87586ED4D87F814FD4414E4CA7BB52 |
|
CONTENT
ssdeep
|
192:gZB0G9LVP0GBc0GEKHfFGv4Iz/gEdp9piD1+kYXsyKB9EyaJ3w0RpDPqfLfeiT9Q:gZV4Iz4o7u+kLyKB9z4xlHdniNY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99996666cccd7630 |
|
VISUAL
aHash
|
381c1c1c18383838 |
|
VISUAL
dHash
|
6278903030696061 |
|
VISUAL
wHash
|
3c3c1c3c3c3c3c3c |
|
VISUAL
colorHash
|
38003018000 |
|
VISUAL
cropResistant
|
6278903030696061 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.