Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C67264369249692B0323D6CC6C61B766E2C3A15ECE670E0193B89D8D7BC3F19DC055BB |
|
CONTENT
ssdeep
|
192:lmGGCe31VVPU0IHt8aIc6Pd7/0RrtFx0kC3LKdITSP7ZKFD1hAWE0Xp6rV+WPsGy:kJ1jraIc6PitRGRSE1ZI4GL+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d719287775362859 |
|
VISUAL
aHash
|
00ffffe7ffffffff |
|
VISUAL
dHash
|
0369796868696914 |
|
VISUAL
wHash
|
00fcfce4fcfce400 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
6869696870696914,80472721c4c3cb05 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)