Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D1F2613260449E3F129382CBB7787F8EE2D6D649CB631A1663F4834D07D6E90CD365A6 |
|
CONTENT
ssdeep
|
768:/9BzzU+INSS6ABa5kFj4XV1yJ2bZrecRq:vzQ+IPBa5Cj4XVsJIZreb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c342bc49c3b667a3 |
|
VISUAL
aHash
|
000020342c20ffff |
|
VISUAL
dHash
|
d0f1ccccc9c82e2a |
|
VISUAL
wHash
|
4010247e7c20ffff |
|
VISUAL
colorHash
|
1a2000080c0 |
|
VISUAL
cropResistant
|
b2f2eacaee9a9a61,bf9eb6f1f2c6c4c8,40082d22aaaa2a2a,d89069ccccc9c8c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)