Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2427573A600CC2E8D9B918CF2C49589515ED345FB3148C6B2A091BF7BC8DF029B53AD |
|
CONTENT
ssdeep
|
384:SHncNcbcIg33xTpmMCCgfMmUFCoTGu4vqGiG:SHncNcbcIg4fBUsyGu4vqGiG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec63936c9a936c2c |
|
VISUAL
aHash
|
fff3f3f3d3f3ffff |
|
VISUAL
dHash
|
0006262626260600 |
|
VISUAL
wHash
|
3f3101010101033e |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
0006262626260600,fcb3f8f8fdffffff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)