Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A7C31A71B501B137633361E2B0764B693267920ECD170E50B3BCE6D6ABEACD268375C6 |
|
CONTENT
ssdeep
|
768:6hXHYjLYjJYjNYjlYjPYjvYjqYjv3AYjIjYjhYjKYjZYjGOwZiZcH1RZ34TVfZXI:k8jICDi9CJ1ylB1p3C7y3UfvQV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dfbc20413fdf8824 |
|
VISUAL
aHash
|
4082ffbc00787800 |
|
VISUAL
dHash
|
d21e3878d0d0c137 |
|
VISUAL
wHash
|
7e87bfbc18787800 |
|
VISUAL
colorHash
|
38003000180 |
|
VISUAL
cropResistant
|
968ccc6cfcec0081,9d9a2b25a8a298d8,9dc5a525d3caf2b8,d21e3878d0d0c137 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 403 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)