Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10FD194634164383B417782CDBE51BF2CD8E7C12ECB5A2C0182EC9B5D1EE5DE0E9152AB |
|
CONTENT
ssdeep
|
96:IZfLDW4QkpICGE/XWKzrZizRYrHiXKkn9ebmw0g9If:MZZ0Kz9RseawRY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4b41ccbcacaab34 |
|
VISUAL
aHash
|
ff0002ffffff1c00 |
|
VISUAL
dHash
|
209696000c08b0c8 |
|
VISUAL
wHash
|
ff0000ffffff0000 |
|
VISUAL
colorHash
|
07c00040040 |
|
VISUAL
cropResistant
|
2094962f100c0810,677f7c6dfdd9f8fe,1324343575753125,1b1f0d0545414101,a0e0f4b4b1c9d2d8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)