Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17352EF315456B97302C381D5AF3653AFB3E28285CA231A4592F4C38DAFDAE46EE1714A |
|
CONTENT
ssdeep
|
384:kOEC3zzWZkIsSQIU/o8H9u8ERUIMm3kIkre:kOEmXWZRxuoM9QRBMmhOe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ccc766631939ccc |
|
VISUAL
aHash
|
06103c1c18180404 |
|
VISUAL
dHash
|
cc25317233724c1c |
|
VISUAL
wHash
|
e797bd1f1918240e |
|
VISUAL
colorHash
|
38e00010000 |
|
VISUAL
cropResistant
|
82848c289ad25abc,c494b9d555315149,cc25317233724c1c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)