Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18DF2CDFEB250979429B393E49A01F9A1369950FFFA4D6350C2B4C46A3CB11F4C89E6E4 |
|
CONTENT
ssdeep
|
384:EPqE//EHfKOCxjvKgUctXY06VHgbK5buxq9hMucffxYx/8Azh1lZ/pEy5cQV3DML:C1cqxmgcHgbSb2qDZxDMALA8KK6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb4d48f6b2f0b842 |
|
VISUAL
aHash
|
000039ffffff0000 |
|
VISUAL
dHash
|
0573f3004c0cc1c5 |
|
VISUAL
wHash
|
0000ffffffff0000 |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
0573f3004c0cc1c5,0129415353f3f3f3,c8c830c4c8918146 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.