Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15B62307620048D3B91C3DAE9AFB5732B72C2D39ADA471A0686F4D3CA9FC6D69CC17501 |
|
CONTENT
ssdeep
|
192:Plse9mFbsD5scaddsVrQhwt3QwSFf+5CRszUGuQld1Q/3Qu:Ple5i59odsVrft9cXiVC3Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c51b3d8ccf399c8 |
|
VISUAL
aHash
|
ff0019131b1f0707 |
|
VISUAL
dHash
|
b24db3b7b3b3cfff |
|
VISUAL
wHash
|
ff001b1b1f1f0707 |
|
VISUAL
colorHash
|
32038000000 |
|
VISUAL
cropResistant
|
0010484c4c4c1008,b24db3b7b3b3cfff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5752 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)