Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7C184635164383B417782CDBE91AF2CD8E7C12ECB1A2C0182EC9B5D1EE5DE0E91419B |
|
CONTENT
ssdeep
|
96:ZZfLDW4QkpICGE/XW8jOYrZizRYrHiXKkn9ebmw0g9If:nZZ08r9RseawRY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4b41ccbcacaab34 |
|
VISUAL
aHash
|
ff0003ffffff0000 |
|
VISUAL
dHash
|
20968e000c08f4c8 |
|
VISUAL
wHash
|
ff0000ffffff0000 |
|
VISUAL
colorHash
|
07c00040040 |
|
VISUAL
cropResistant
|
20949e2f14080810,130f0d4541414101,677f7c6dedf9f8fc,9324343535656575,a0e0f4b4c9c9d2d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)