Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18CB29272A008253F52138FE4E2623B2EB2E6D38DDB970584A6FC47A45FEBC90DC75615 |
|
CONTENT
ssdeep
|
768:roJuN4QxQWpG/4scrzJNJ0JIJEJnJsBy5LVKaL8u38Yo/NSI3VTCfU:fNJpbrdrsocnOoZZnsFlSI3VTCM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e548b2c9b29ae38d |
|
VISUAL
aHash
|
fd00000000f9ffff |
|
VISUAL
dHash
|
19c6c2e4f2c3140f |
|
VISUAL
wHash
|
ff00300000f9ffff |
|
VISUAL
colorHash
|
03006000000 |
|
VISUAL
cropResistant
|
0009611919610080,c6c1f6f3c308160d,c48c989080406130,92ccf86029b0b3e7,c0f0c6c2e5b6f3c3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)