Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19411C0B640008C872700D3C465657229BAC2D5668E935EC49BF5B3AD2BD2EA3CD521C7 |
|
CONTENT
ssdeep
|
12:hRwMwrwV2HTCESIBFxqdKgwJS/qM4H76VPRoJD9kJDVfO3gs2Kt5pbV7Ts9KtCi1:hR/LgzJLmMgLS3bKiN92IQs2E/T2Nq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c077683f868971e |
|
VISUAL
aHash
|
03019c191c3a10c0 |
|
VISUAL
dHash
|
8f6730b370f2332c |
|
VISUAL
wHash
|
47159c791e3f98c2 |
|
VISUAL
colorHash
|
31200008040 |
|
VISUAL
cropResistant
|
9597d272635242c3,e4d490f8f0e4f47e,dbdbc9d8d2c9c8c9,9b9896919e1e9bda,b093989e4e869677,d8e2e68686ce2e26,8f6730b370f2332c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)