Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19652686111C4983B0792C1D9CA32F729D682C39DCD461A06F9F4576F9EF6FA3EC021A9 |
|
CONTENT
ssdeep
|
192:2X7K2u4guapbq0m2+TadMcTTAhDN3STIc/SOoKw640M:2v7kbE2+Tadpnj/SrKw640M |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bb39c6c4e8c6c4d4 |
|
VISUAL
aHash
|
0f0f0f090fffffff |
|
VISUAL
dHash
|
585a3b5b3b797d0b |
|
VISUAL
wHash
|
0f0f0f090f3f1fc1 |
|
VISUAL
colorHash
|
06600030000 |
|
VISUAL
cropResistant
|
585a3b5b3b797d0b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)