Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T172832AF6539867B6424383D5A331564A73F6B0B9FF538B50C3F896DA5E92CE4CC2A480 |
|
CONTENT
ssdeep
|
768:GzlXM7Xjx5Vh8v/cyO1pyjcNRG1envzmaxWmmmN1RtActWJxwjJvzmaxrmmmT18M:EI1b1maxj37W8tmaxqQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e849b5954d49b369 |
|
VISUAL
aHash
|
fff8c0d0d8ffffff |
|
VISUAL
dHash
|
2a111333332627cc |
|
VISUAL
wHash
|
fbf0808090ff93c7 |
|
VISUAL
colorHash
|
0e0000003c0 |
|
VISUAL
cropResistant
|
2a111333332627cc,070f49c5d4350932 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)