Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T181520F719456B97303C382D1AF3653AFB3E28285CA234B4592F4C38DAFDAE46DE13149 |
|
CONTENT
ssdeep
|
384:kOEu25ixm7wvIsSQIU/b8H9u8ERUISm3kIO1R6:kOEJr7wQxubM9QRBSmhs6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ccc766631939ccc |
|
VISUAL
aHash
|
06103c1c18180404 |
|
VISUAL
dHash
|
cc25317233724c1c |
|
VISUAL
wHash
|
e797bd1f1918240e |
|
VISUAL
colorHash
|
38e00010000 |
|
VISUAL
cropResistant
|
82848c289ad25abc,c494b9d555315149,cc25317233724c1c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)