Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13E111410005C8CBAA181E1E417E18A1A39D9C257CF530A005BF4CBBD6AE2E85CE2B595 |
|
CONTENT
ssdeep
|
12:hbMwLdkpi+ph6IjduAatvXKXcg/xLtRTKeoJD9kDVoFRBwXmugxxPeGuY8+O036m:hAXIlvaMmxJRqN9uzXpixPoY0A6xZS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9cc90f3e3823279d |
|
VISUAL
aHash
|
19fd7e469e141e00 |
|
VISUAL
dHash
|
f3b3f0bc3c2c7032 |
|
VISUAL
wHash
|
1bfd7f469e043e00 |
|
VISUAL
colorHash
|
07000018009 |
|
VISUAL
cropResistant
|
fff3b3b3b2f1a894,f8f8f1f0a32323a3,f8c8889c9ca868d6,ffeff3f3a8b0b1f3,f0bcbc382c6c7036,1108303232300841,e6c6a66e94b484ae |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)