Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BCC3D9A34118257E19571BC0A718172FBCC1908EEE9B16D6B2FEC3A412FBCD1B572693 |
|
CONTENT
ssdeep
|
3072:OiiX6e8zBdwwRHcJech+umWoshapMuBFwFk0QP/Jp8Ata:OiiXh8zBVHcJee+umWrhapMmWl0/Lta |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edcd3292926cc794 |
|
VISUAL
aHash
|
fff3f3d3cbfbc3c3 |
|
VISUAL
dHash
|
29363616360b970b |
|
VISUAL
wHash
|
ff93f38183c3c181 |
|
VISUAL
colorHash
|
06000000c00 |
|
VISUAL
cropResistant
|
29363616360b970b,72acaab2a4baa646,334d96ba69494b67,db1b3b96d6eaea8e,8e969696860b8f96,04922e9090de829c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 943 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)