Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB033F32A0449E3F16D7C2D26BB06B5EF3D6E289CA671A1663F8831C17C7E90CD31956 |
|
CONTENT
ssdeep
|
384:Vp5KmV0VSJO+ISOB+9cMpw27fP33v0yQW7sJmBIMLWHCCUnAsSujF/9qeq:VpUm8Z+I6fVP0yBb1LWiznAsUeq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c689c19e99b89acd |
|
VISUAL
aHash
|
ff70000010040060 |
|
VISUAL
dHash
|
63c7e575676dc4c2 |
|
VISUAL
wHash
|
ff73331113947074 |
|
VISUAL
colorHash
|
30000000180 |
|
VISUAL
cropResistant
|
718d544343434344,0008046870702004,c6e73573652dc6c6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)