Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D33813A51046E7F11D382D27BB53B5EE3D6D248CB43465AA3E8834E03D7E80CD369A6 |
|
CONTENT
ssdeep
|
768:HMOKmxL+IV+zr8HDgjqYre5ltOUFlzKKEN7oo/zbn5RqA0Uq:PfxL+IaAjVPz9K7ZzqA0t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f648c9369136cb39 |
|
VISUAL
aHash
|
f0f0f0e6868686fc |
|
VISUAL
dHash
|
6424242c2c2c2c10 |
|
VISUAL
wHash
|
f0f0f0e6868686fc |
|
VISUAL
colorHash
|
03000008030 |
|
VISUAL
cropResistant
|
713113333333370c,14d8e6c470246458,6424242c2c2c2c10 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)