Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B1E1B52FC25806101F20C559B9B523DDD35E504CF3524FEA6EE8D02C72AA6914FB67DB |
|
CONTENT
ssdeep
|
192:XYEXoTP9WbIktMkp+2qSP/TRgz9ikUoTf+ZEVaeyY:U79WbIktMkk2qSY+YmKaeyY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bdd29268c26c3e93 |
|
VISUAL
aHash
|
ffffbfffff81817f |
|
VISUAL
dHash
|
ac3b3b631b2b33e0 |
|
VISUAL
wHash
|
fe0b0999fb81811f |
|
VISUAL
colorHash
|
07200000600 |
|
VISUAL
cropResistant
|
ac3b3b631b2b33e0,139dcdcf98adad54,a9acd69ce28e2c8c,69ac9c8c9a4cd819,a0a78eae8c8c9a15 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)