Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A2365F290A4D077078EF6E0B566671FB7C3878BD9460FE29AE847185E86DC18E1341A |
|
CONTENT
ssdeep
|
768:01gMkvdq3FGMq6COFXQdC3gf6IgMkvdq3FGMq6COd2/RPdXwlfK98c2705C81O7z:01gMkvdq3FGMq6COFXQdC3gfNgMkvdqz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
953e6f634c1511dc |
|
VISUAL
aHash
|
00005e7e7e6e7e7e |
|
VISUAL
dHash
|
41ecb4b2f2cac6f2 |
|
VISUAL
wHash
|
00005e5e7e6e7e7a |
|
VISUAL
colorHash
|
0e007000000 |
|
VISUAL
cropResistant
|
3222b2b29acad2f2,41ecb4b2f2cac6f2,41536766494919b9,1b91711d27c3c666 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)