Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1787308B15248A7BB134343D56331674B73E2A0A8FF434A64C3E992EE6E97CE0DC27594 |
|
CONTENT
ssdeep
|
768:aGkf7Xjx5Vh8v/cyO1pyjcNRG12NmmmN1P5wLlJ9W7wlP3gmmmT18j5e:aYI1b/KOLlJ9W7w5Ag |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e84bb7954ac9b348 |
|
VISUAL
aHash
|
fff8c0f0d8ffffff |
|
VISUAL
dHash
|
6b111333332623cc |
|
VISUAL
wHash
|
f98080c090ffdbe7 |
|
VISUAL
colorHash
|
0e0000003c0 |
|
VISUAL
cropResistant
|
6b111333332623cc,070f49c5d4350932 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)