Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1302243716849A93B1293D2C55BA6A33FA391828BFE574F92B2F8D79C4FC6D40DD31201 |
|
CONTENT
ssdeep
|
96:JOVoS6SISBxy4MSJSJSrZfTWCd59hxShcKVl7Q9Q/BSlIetaVg5H/54of5x1g+:4hjBB744rIa9+VTZg5f54Oxz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c9d71a473374c71 |
|
VISUAL
aHash
|
1a1f1f3f1f1f0f00 |
|
VISUAL
dHash
|
f4f2f2fdf2b6fb32 |
|
VISUAL
wHash
|
0a1f1f3f1f1f0f00 |
|
VISUAL
colorHash
|
08c00080000 |
|
VISUAL
cropResistant
|
7df69ab83cf4dcd2,84c15c2d0e25b1b2,8280801727808282,f4f2f2fdf2b6fb32 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)