Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17E924D29B54A1C62DF73C4C3E4E02D272499E3078A2A09E157E905B59FD3CF1B989FB4 |
|
CONTENT
ssdeep
|
96:0iryG1T0aP6kZxhHQE0BW/q2rE5agQI6XLHk+fc8BzSzILlaBkdz2cTsyIz3Ap0L:0i7TpQEs6bkl0zNUbVX/0/6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dcdd73f1e6260809 |
|
VISUAL
aHash
|
e7fc181818180000 |
|
VISUAL
dHash
|
0f32b3333332440e |
|
VISUAL
wHash
|
ffff3c3c3c3c0000 |
|
VISUAL
colorHash
|
39600008200 |
|
VISUAL
cropResistant
|
06066669c30f0684,0008bc98b9b7bc9d,0f00000000000008,a6a294554d3931c2,0f32b3333332440e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)