Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DBE1632F9248233A1722C165A58B72C5E71F441CC7B19AEA49FCC0DC2739B315A7A8DF |
|
CONTENT
ssdeep
|
96:vj8tN38tC8t4Tnw/Ealdjjiauz0e0KvDUoSv3ly3OF6QsREsk5E8P7aQfKK9LJHo:qFTnwM6o1go21SOuu5E8PlfK8LS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a42499d8dcee9b83 |
|
VISUAL
aHash
|
c3030383f77fff7f |
|
VISUAL
dHash
|
96164e262ed9c7f2 |
|
VISUAL
wHash
|
c3030383073f3f3f |
|
VISUAL
colorHash
|
06038000000 |
|
VISUAL
cropResistant
|
96164e262ed9c7f2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)