Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C543747013182E3DA51787A4E665B73A11AE9388E64F916CF17C01712FCBC99EC7B2D4 |
|
CONTENT
ssdeep
|
768:1wGesj2CPwx4Rq4324Ydm4Ms4F04ewjtD+sPBH4RNaakYbUth:bb2TW9E8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba63cd4d11c64733 |
|
VISUAL
aHash
|
fb83878783c3df8f |
|
VISUAL
dHash
|
233f2d2d0f2b3434 |
|
VISUAL
wHash
|
b58187878381df8f |
|
VISUAL
colorHash
|
0f001040600 |
|
VISUAL
cropResistant
|
233f2d2d0f2b3434,8e1e161a3a382323,401be4c4e4241100,7e8e8eceee8c8d7e,d293cbc3d3c393e7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)