Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BD451BF013281A3BA08BC39DDB79BDE622AD99D6EA83454493AE4BEC57C7CC4DD055C0 |
|
CONTENT
ssdeep
|
12288:F4d7LZLCinAtOSb/UrtCzqqXSQaDqYzMaC5:abjSZ2RD5zMaC5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f72037e66497e03 |
|
VISUAL
aHash
|
00ffffbf939b3b37 |
|
VISUAL
dHash
|
756064662723f2d4 |
|
VISUAL
wHash
|
003f3f1391933b37 |
|
VISUAL
colorHash
|
06003000080 |
|
VISUAL
cropResistant
|
757a64672722f2d4,001101b1b1090100,61f0f67272b68e6d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)