Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2429461B5AA5977025F47CA73B65B0A73D0C306C743050266FD836C0BE6DB1EED211E |
|
CONTENT
ssdeep
|
192:R04JpdOhYvjh6djd8Bj74N1FAP7a2y1tfERBlg6g3jgKlCZgkwgf:uCvjajAj7Cw+2y1Ig6g3jgKGgzgf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce56b160e5b54da8 |
|
VISUAL
aHash
|
feb438b0f0f0ffff |
|
VISUAL
dHash
|
4465616165655a01 |
|
VISUAL
wHash
|
fe1410303030ffff |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
4465616165655a01,53593d755569255b,4e63739d8dd3d351,232358585f595a5a,a4c4e190d0c1c524 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)