Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11EB2B779E2C86ABF319B0467F915BFD0E04EE64BD37B5C5AB2ACD58627ECC024D20164 |
|
CONTENT
ssdeep
|
384:6rJ8auB0xSVnQLEdHt01gl4HMwFF+MdFm9MeFzUMrF8LM0FpyMBJjgtvQFpQIN:6rJ8auqKGqyHMwX+Mdg9MexUMrCLM0bj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92b04d29e56d6dc3 |
|
VISUAL
aHash
|
040e6e0e0e007070 |
|
VISUAL
dHash
|
bccccccccc34c8c8 |
|
VISUAL
wHash
|
466e7e4e4e007c7c |
|
VISUAL
colorHash
|
39007000000 |
|
VISUAL
cropResistant
|
8c0f72747c7c1c71,f2e0b0b071eab0b0,bccccccccc34c8c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)